Data processing method and apparatus

By protecting and encrypting the data units of the protocol layer at the lower level of the PDCP layer, the security risks of pseudo-base station attacks on other user-side PDUs are solved, the security performance and user experience of data transmission are improved, and signaling overhead and processing delay are reduced.

WO2025139887A1PCT designated stage expired Publication Date: 2025-07-03HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/139703
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-29
Filing Date
2024-12-16
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

In the prior art, pseudo-base station attacks forgery or monitor other user plane PDUs except user plane data PDUs, causing serious security risks. The existing security processing is limited to user plane data PDUs at the PDCP layer, and no other PDUs are safely processed.

Method used

A data processing method is provided, by protecting and encrypting the data units of the lower protocol layer of the PDCP layer, verifying the integrity of the data units using the first verification code, and protecting and encrypting the PDUs of the higher protocol layer, reducing signaling overhead and improving data transmission security performance.

Benefits of technology

Effectively identify and prevent the use of data units by pseudo-base stations or illegal terminals, improve user service experience and data transmission security performance, and reduce signaling overhead and data processing delays.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024139703_03072025_PF_FP_ABST
    Figure CN2024139703_03072025_PF_FP_ABST
Patent Text Reader

Abstract

A data processing method and apparatus, which can perform integrity protection on data units of a lower protocol layer of a packet data convergence protocol (PDCP) layer and improve the security performance of data transmission, thereby improving the user experience. The method comprises: a first communication apparatus determining a plurality of data units of a first protocol layer, and a first verification code, and sending a first protocol data unit (PDU) that comprises the plurality of data units and the first verification code, wherein the first protocol layer is a lower protocol layer of a PDCP layer, and the first verification code is configured to verify the integrity of the plurality of data units; and a second communication apparatus receiving the first PDU, determining a second verification code, and determining, on the basis of the first verification code and the second verification code, whether the plurality of data units have been changed, wherein the second verification code is configured to verify the integrity of the plurality of data units.
Need to check novelty before this filing date? Find Prior Art

Description

Data processing method and device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 29, 2023, with application number 202311866084.2 and application name “Data Processing Method and Device”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The embodiments of the present application relate to the field of communications, and in particular to a data processing method and apparatus. Background Art

[0003] In wireless communications, communication security is a crucial factor, ensuring the safety of user data. Rogue base station attacks are a common threat to wireless security. These are illegal base stations typically comprised of simple wireless devices and specialized open-source software.

[0004] Currently, although security processing, such as encryption and / or integrity protection, can be performed on information between the terminal and the base station after security mode is enabled, this security processing is limited to the user plane protocol data unit (PDU) of the packet data convergence protocol (PDCP) layer. No security processing is currently performed on other user plane PDUs.

[0005] However, in addition to user plane data PDUs, many other user plane PDUs carry important control information. If they are used by fake base stations or illegal terminals to forge or monitor these user plane PDUs, it will bring great security risks. Summary of the Invention

[0006] The present application provides a data processing method and device, which can improve the security performance of data transmission.

[0007] In a first aspect, a data processing method is provided. The method can be performed by a first communication device, or by a module (e.g., a processor, a chip, or a chip system) applied to the first communication device, or by a logical node, a logical module, or software that implements all or part of the functions of the first communication device. The method includes: determining multiple data units of a first protocol layer, where the first protocol layer is a lower protocol layer of a packet data convergence protocol (PDCP) layer; determining a first verification code for verifying the integrity of the multiple data units; and outputting a first protocol data unit (PDU) including the multiple data units and the first verification code.

[0008] Based on this solution, the transmitting end can perform integrity protection on the data units of the first protocol layer. Since the first protocol layer is located below the PDCP layer, or is a relatively low-level protocol layer, it can be considered that the solution of the present application performs integrity protection on the data units of the low-level protocol layer, so that the receiving end can verify the integrity of the data units of the low-level protocol layer, thereby identifying whether there is a malicious attack, and then taking corresponding measures to improve the user's service experience. Since the PDU of the high-level protocol layer is usually used as the data unit of the low-level protocol layer, it can be considered that the solution of the present application performs integrity protection on the PDU of the high-level protocol layer (including the user plane PDU and the control plane PDU) at the first protocol layer, thereby preventing fake base stations or illegal terminals from using these PDUs, thereby improving the security performance of data transmission. In addition, the result of integrity protection of multiple data units is a verification code (i.e., the first verification code), which can reduce signaling overhead compared to each data unit corresponding to a verification code.

[0009] In one possible design, determining the first verification code includes: determining verification codes corresponding to multiple data units respectively, and then determining the first verification code based on the verification codes corresponding to the multiple data units respectively.

[0010] Based on this possible design, the first communication device first determines the verification codes corresponding to the multiple data units and then determines the first verification code based on the verification codes corresponding to the multiple data units. Therefore, integrity protection can be performed immediately after the first communication device obtains the data unit. This eliminates the need to wait for the first protocol layer entity to complete assembly of the first PDU before performing integrity protection, reducing data processing latency and improving service performance.

[0011] In one possible design, the first verification code is an exclusive OR of verification codes corresponding to multiple data units; or, the first verification code is a verification code obtained by performing integrity protection on verification codes corresponding to multiple data units.

[0012] Based on this possible design, after performing XOR or integrity protection on the verification codes corresponding to the multiple data units, a first verification code is obtained and sent. Compared with sending the verification code corresponding to each data unit, signaling overhead can be reduced.

[0013] In one possible design, the multiple data units include a first data unit. The verification code corresponding to the first data unit is obtained based on the first data unit and at least one of the following: a key, a value corresponding to the first PDU, a transmission direction of the first PDU, a hybrid automatic repeat request HARQ identifier corresponding to the first PDU, a logical channel identifier LCID corresponding to the first data unit, a radio bearer identifier corresponding to the first data unit, or a type parameter of the first data unit, and the value corresponding to the first PDU is used to identify the first PDU, or to indicate the time domain and / or frequency domain position of the first PDU.

[0014] In one possible design, multiple data units include a first data unit, the first PDU includes a first sub-PDU, and the first data unit is located in the first sub-PDU; the sub-header of the first sub-PDU includes first information, and the first information is used to indicate that integrity protection is performed on the first data unit.

[0015] Based on this possible design, the sending end can indicate which data units are integrity protected, so that the receiving end can clearly identify the data units that need to be integrity verified, thereby determining the second verification code based on the correct data units and improving the accuracy of the integrity verification.

[0016] In one possible design, the first PDU includes a second sub-PDU, the first verification code is located in the second sub-PDU, and the sub-header of the second sub-PDU includes length information of the first verification code.

[0017] Based on this possible design, the sending end indicates the length information of the first verification code, which can help the receiving end obtain the first verification code more accurately and improve the accuracy of integrity verification.

[0018] In one possible design, determining multiple data units of the first protocol layer includes: determining multiple data units of the first protocol layer based on at least one logical channel identifier LCID or at least one logical channel group LCG identifier, wherein the data unit corresponding to the at least one LCID or LCG identifier is a data unit that requires integrity protection. The at least one LCID includes the LCID of each data unit in the above-mentioned multiple data units, or the at least one LCG identifier includes the LCG identifier of each data unit in the above-mentioned multiple data units.

[0019] Based on this possible design, when at least one LCID or LCG identifier is protocol-defined or pre-configured, both the sender and the receiver can determine the data units that need to be integrity protected / verified based on at least one LCID or LCG identifier, so that the sender does not need to send information to the receiver to indicate which data units are integrity protected, which can save signaling overhead.

[0020] In one possible design, determining a first verification code includes: determining a first input parameter, and determining the first verification code based on the first input parameter. The first input parameter includes a first bit stream and at least one of the following: a key, a numerical value corresponding to the first PDU, a transmission direction of the first PDU, or a hybrid automatic repeat request HARQ identifier corresponding to the first PDU. The first bit stream is a collection of multiple data units, or the first bit stream is a collection of sub-PDUs in which multiple data units are located. The numerical value corresponding to the first PDU is used to identify the first PDU or to indicate the time domain and / or frequency domain position of the first PDU.

[0021] Based on this possible design, since the first bit stream is a collection of multiple data units, or the first bit stream is a collection of sub-PDUs containing multiple data units, only one integrity protection algorithm operation is required during the determination of the first verification code, thereby reducing computational overhead. Furthermore, when the first bit stream is a collection of sub-PDUs containing the aforementioned multiple data units, integrity protection is also performed on the sub-headers corresponding to the multiple data units, further improving security performance.

[0022] In one possible design, the multiple data units are all data units in a first PDU, and the header of the first PDU includes second information, where the second information is used to indicate that integrity protection is performed on the first PDU or all data units of the first PDU.

[0023] In one possible design, the first PDU is located in a first transport block (TB); the multiple data units are all data units in the first PDU. The method further includes: determining scheduling information for the first TB, the scheduling information including third information, the third information being used to indicate that the PDU included in the first TB or all data units in the PDU require integrity protection.

[0024] In one possible design, the multiple data units are partial data units in a first PDU, and the header of the first PDU includes fourth information, which is used to indicate that integrity protection is performed on the multiple data units or the sub-PDU where the multiple data units are located.

[0025] Based on the above three possible designs, the sender can indicate which data units are integrity protected, so that the receiver can clearly identify the data units that need to be integrity verified, thereby determining the second verification code based on the correct data units and improving the accuracy of integrity verification.

[0026] In one possible design, the fourth information includes a bitmap, where the bitmap includes M bits, where M is the total number of data units in the first PDU, and the M bits correspond one-to-one to the M data units or M sub-PDUs in the first PDU. Wherein, when the value of the first bit in the M bits is a preset value, it indicates that integrity protection is performed on the data unit or sub-PDU corresponding to the first bit, and the first bit is any bit in the M bits.

[0027] In one possible design, when the value corresponding to the first PDU is used to identify the first PDU, the value corresponding to the first PDU is a sequence number SN or a count value COUNT; when the value corresponding to the first PDU is used to indicate the time domain and / or frequency domain position of the first PDU, the value corresponding to the first PDU is any one of the following: the system frame number SFN where the first PDU is located, a value obtained based on the SFN and the super system frame number H-SFN where the first PDU is located, an index of the time domain resource where the first PDU is located, or a value of a time-frequency resource indication field. The value of the time-frequency resource indication field indicates the time-frequency resource used to carry the first PDU.

[0028] In one possible design, the first protocol layer is the media access control MAC layer, and the data unit includes a MAC service data unit SDU or a MAC control element CE.

[0029] In the second aspect, a data processing method is provided, which can be executed by a second communication device, or by a module (such as a processor, chip, or chip system, etc.) applied to the second communication device, or by a logical node, logical module or software that can realize all or part of the functions of the second communication device. The method includes: receiving a first protocol data unit PDU, the first PDU includes multiple data units of a first protocol layer and a first verification code, the first protocol layer is a lower protocol layer of the packet data convergence protocol PDCP layer, and the first verification code is used to verify the integrity of the multiple data units; determining a second verification code, the second verification code is used to verify the integrity of the multiple data units; and determining whether the multiple data units have been changed based on the first verification code and the second verification code. Among them, the technical effects brought about by the second aspect can refer to the technical effects brought about by the above-mentioned first aspect, and will not be repeated here.

[0030] In one possible design, determining the second verification code includes: determining verification codes corresponding to multiple data units respectively, and determining the second verification code based on the verification codes corresponding to the multiple data units respectively.

[0031] In one possible design, the second verification code is an exclusive OR of the verification codes corresponding to the multiple data units; or, the second verification code is a verification code obtained by performing integrity protection on the verification codes corresponding to the multiple data units.

[0032] In one possible design, the multiple data units include a first data unit. The verification code corresponding to the first data unit is obtained based on the first data unit and at least one of the following: a key, a value corresponding to the first PDU, a transmission direction of the first PDU, a hybrid automatic repeat request HARQ identifier corresponding to the first PDU, a logical channel identifier LCID corresponding to the first data unit, a radio bearer identifier corresponding to the first data unit, or a type parameter of the first data unit, and the value corresponding to the first PDU is used to identify the first PDU, or to indicate the time domain and / or frequency domain position of the first PDU.

[0033] In one possible design, multiple data units include a first data unit, the first PDU includes a first sub-PDU, and the first data unit is located in the first sub-PDU; the sub-header of the first sub-PDU includes first information, and the first information is used to indicate that integrity protection is performed on the first data unit.

[0034] In one possible design, the method further includes: determining at least one logical channel identifier LCID or at least one logical channel group LCG identifier, wherein the data unit corresponding to the at least one LCID or LCG identifier is a data unit that requires integrity protection. The at least one LCID includes the LCID of each data unit in the above-mentioned multiple data units, or the at least one LCG identifier includes the LCG identifier of each data unit in the above-mentioned multiple data units.

[0035] In one possible design, determining the second verification code includes: determining a first input parameter, and determining the second verification code based on the first input parameter. The first input parameter includes a first bit stream and at least one of the following: a key, a value corresponding to the first PDU, a transmission direction of the first PDU, or a hybrid automatic repeat request HARQ identifier corresponding to the first PDU. The first bit stream is a collection of multiple data units, or the first bit stream is a collection of sub-PDUs in which multiple data units are located; the value corresponding to the first PDU is used to identify the first PDU or to indicate the time domain and / or frequency domain position of the first PDU.

[0036] In one possible design, the multiple data units are all data units in a first PDU, and the header of the first PDU includes second information, where the second information is used to indicate that integrity protection is performed on the first PDU or all data units of the first PDU.

[0037] In one possible design, the first PDU is located in a first transport block (TB); the multiple data units are all data units in the first PDU. The method further includes: determining scheduling information for the first TB, the scheduling information including third information, the third information being used to indicate that the PDU included in the first TB or all data units in the PDU require integrity protection.

[0038] In one possible design, the multiple data units are partial data units in the first PDU, and the header of the first PDU includes fourth information, and the fourth information is used to indicate that integrity protection is performed on the multiple data units or the sub-PDU where the multiple data units are located.

[0039] In one possible design, when the value corresponding to the first PDU is used to identify the first PDU, the value corresponding to the first PDU is a sequence number SN or a count value COUNT; when the value corresponding to the first PDU is used to indicate the time domain and / or frequency domain position of the first PDU, the value corresponding to the first PDU is any one of the following: the system frame number SFN where the first PDU is located, a value obtained based on the SFN and the super system frame number H-SFN where the first PDU is located, an index of the time domain resource where the first PDU is located, or a value of a time-frequency resource indication field. The value of the time-frequency resource indication field indicates the time-frequency resource used to carry the first PDU.

[0040] In one possible design, the first protocol layer is the media access control MAC layer, and the data unit includes a MAC service data unit SDU or a MAC control element CE.

[0041] Among them, the technical effects brought about by any possible design in the second aspect can refer to the technical effects brought about by the corresponding design in the above-mentioned first aspect, and will not be repeated here.

[0042] In a third aspect, a data processing method is provided. The method can be executed by a first communication device, or by a module (e.g., a processor, a chip, or a chip system) applied to the first communication device, or by a logical node, a logical module, or software that implements all or part of the functions of the first communication device. The method includes: determining multiple data units of a first protocol layer, where the first protocol layer is a lower protocol layer of a packet data convergence protocol (PDCP) layer; determining a first ciphertext, where the first ciphertext is obtained by encrypting the multiple data units; and outputting a first protocol data unit (PDU) including the first ciphertext.

[0043] Based on this solution, the sending end can encrypt the data units of the first protocol layer. Since the first protocol layer is located below the PDCP layer, or is a relatively low-level protocol layer, it can be considered that the solution of this application encrypts the data units of the low-level protocol layer. Since the PDU of the high-level protocol layer is usually used as the data unit of the low-level protocol layer, it can be considered that the solution of this application encrypts the PDU of the high-level protocol layer (including the user plane PDU and the control plane PDU) at the first protocol layer, thereby preventing the leakage of information carried by the data unit and preventing illegal devices from changing the data unit, thereby improving the security performance of data transmission and user experience.

[0044] In one possible design, determining the first ciphertext includes: determining ciphertexts corresponding to multiple data units respectively, and determining a first verification code based on the ciphertexts corresponding to the multiple data units respectively.

[0045] Based on this possible design, the first communication device first determines the ciphertext corresponding to each of the multiple data units and then determines the first ciphertext based on the ciphertext corresponding to each of the multiple data units. Therefore, encryption can be performed immediately after the first communication device obtains the data unit. This eliminates the need to wait for the first protocol layer entity to complete assembly of the first PDU before performing encryption, reducing data processing latency and improving service performance.

[0046] In one possible design, the first ciphertext is a collection of ciphertexts corresponding to multiple data units.

[0047] In one possible design, the multiple data units include a first data unit. The ciphertext corresponding to the first data unit is obtained based on the first data unit and at least one of the following: a key, a value corresponding to the first PDU, a transmission direction of the first PDU, a hybrid automatic repeat request HARQ identifier corresponding to the first PDU, a logical channel identifier LCID corresponding to the first data unit, a radio bearer identifier corresponding to the first data unit, a type parameter of the first data unit, or a key stream length, and the value corresponding to the first PDU is used to identify the first PDU, or to indicate the time domain and / or frequency domain position of the first PDU.

[0048] In one possible design, multiple data units include a first data unit, the first PDU includes a first sub-PDU, and the ciphertext corresponding to the first data unit is located in the first sub-PDU; the sub-header of the first sub-PDU includes first information, and the first information is used to indicate that the first data unit is encrypted.

[0049] Based on this possible design, the sending end can indicate which data units are encrypted, so that the receiving end can clearly know the data units that need to be decrypted, thereby obtaining plaintext based on the correct data units, thereby improving the efficiency of data transmission.

[0050] In one possible design, determining multiple data units of the first protocol layer includes: determining multiple data units of the first protocol layer based on at least one logical channel identifier LCID or at least one logical channel group LCG identifier, wherein the data unit corresponding to the at least one LCID or LCG identifier is a data unit that needs to be encrypted. The at least one LCID includes the LCID of each data unit in the above-mentioned multiple data units, or the at least one LCG identifier includes the LCG identifier of each data unit in the above-mentioned multiple data units.

[0051] Based on this possible design, when at least one LCID or LCG identifier is protocol-defined or pre-configured, both the sender and the receiver can determine the data units that need to be encrypted / decrypted based on at least one LCID or LCG identifier, so that the sender does not need to send information to the receiver to indicate which data units are encrypted, which can save signaling overhead.

[0052] In one possible design, determining the first ciphertext includes: determining a second input parameter, and determining the first ciphertext based on the second input parameter. The second input parameter includes a first bit stream and at least one of the following: a key, a numerical value corresponding to the first PDU, a transmission direction of the first PDU, a hybrid automatic repeat request HARQ identifier corresponding to the first PDU, or a key stream length. The first bit stream is a collection of multiple data units, or the first bit stream is a collection of sub-PDUs in which multiple data units are located. The numerical value corresponding to the first PDU is used to identify the first PDU, or to indicate the time domain and / or frequency domain position of the first PDU.

[0053] Based on this possible design, since the first bit stream is a collection of multiple data units, or the first bit stream is a collection of sub-PDUs containing multiple data units, only one encryption algorithm operation is required during the process of determining the first ciphertext, thereby reducing computational overhead. Furthermore, when the first bit stream is a collection of sub-PDUs containing multiple data units, the sub-headers corresponding to these multiple data units are also encrypted, further improving security performance.

[0054] In one possible design, the multiple data units are all data units in a first PDU, and the header of the first PDU includes second information, where the second information is used to indicate that the first PDU or all data units of the first PDU are encrypted.

[0055] In one possible design, the first PDU is located in the first transmission block TB; the multiple data units are all data units in the first PDU, and the method also includes: determining the scheduling information of the first TB, the scheduling information includes third information, and the third information is used to indicate that the PDU included in the first TB or all data units in the PDU need to be encrypted.

[0056] In one possible design, the multiple data units are partial data units in a first PDU, and the header of the first PDU includes fourth information, and the fourth information is used to indicate that the multiple data units or the sub-PDU where the multiple data units are located are encrypted.

[0057] Based on the three possible designs described above, the sender can indicate which data units are encrypted, allowing the receiver to clearly identify the data units that need to be decrypted, thereby obtaining plaintext based on the correct data units and improving data transmission efficiency.

[0058] In one possible design, when the value corresponding to the first PDU is used to identify the first PDU, the value corresponding to the first PDU is a sequence number SN or a count value COUNT; when the value corresponding to the first PDU is used to indicate the time domain and / or frequency domain position of the first PDU, the value corresponding to the first PDU is any one of the following: the system frame number SFN where the first PDU is located, a value obtained based on the SFN and the super system frame number H-SFN where the first PDU is located, an index of the time domain resource where the first PDU is located, or a value of a time-frequency resource indication field. The value of the time-frequency resource indication field indicates the time-frequency resource used to carry the first PDU.

[0059] In one possible design, the first protocol layer is the media access control MAC layer, and the data unit includes a MAC service data unit SDU or a MAC control element CE.

[0060] In a fourth aspect, a data processing method is provided, which can be executed by a second communication device, or by a module (such as a processor, chip, or chip system, etc.) applied to the second communication device, or by a logical node, logical module, or software that can implement all or part of the functions of the second communication device. The method includes: receiving a first protocol data unit PDU, the first PDU including a first ciphertext, the first ciphertext being obtained by encrypting multiple data units of a first protocol layer, the first protocol layer being a lower protocol layer of a packet data convergence protocol PDCP layer; decrypting the first ciphertext. Among them, the technical effects brought about by the fourth aspect can refer to the technical effects brought about by the third aspect above, and will not be repeated here.

[0061] In one possible design, the first ciphertext is a collection of ciphertexts corresponding to multiple data units.

[0062] In one possible design, the multiple data units include a first data unit, and the first ciphertext includes the ciphertext corresponding to the first data unit. Decrypting the first ciphertext includes: determining a first key stream based on a third input parameter, XORing the first key stream and the ciphertext corresponding to the first data unit to obtain the first data unit. The third input parameter includes at least one of the following: a key, a numerical value corresponding to the first PDU, a transmission direction of the first PDU, a hybrid automatic repeat request HARQ identifier corresponding to the first PDU, an LCID corresponding to the first data unit, a radio bearer identifier corresponding to the first data unit, a type parameter of the first data unit, or a key stream length. The numerical value corresponding to the first PDU is used to identify the first PDU, or to indicate the time domain and / or frequency domain position of the first PDU.

[0063] In one possible design, multiple data units include a first data unit, the first PDU includes a first sub-PDU, and the ciphertext corresponding to the first data unit is located in the first sub-PDU; the sub-header of the first sub-PDU includes first information, and the first information is used to indicate that the first data unit is encrypted.

[0064] In one possible design, the method further includes: determining at least one logical channel identifier LCID or at least one logical channel group LCG identifier, wherein the data unit corresponding to the at least one LCID or LCG identifier is a data unit that needs to be encrypted. The at least one LCID includes the LCID of each data unit in the plurality of data units, or the at least one LCG identifier includes the LCG identifier of each data unit in the plurality of data units.

[0065] In one possible design, decrypting the first ciphertext includes: determining a second key stream based on a fourth input parameter, and performing an XOR operation on the second key stream and the first ciphertext to obtain a first bit stream. The fourth input parameter includes at least one of the following: a key, a numerical value corresponding to the first PDU, a transmission direction of the first PDU, a HARQ identifier corresponding to the first PDU, or a key stream length. The numerical value corresponding to the first PDU is used to identify the first PDU or to indicate the time domain and / or frequency domain position of the first PDU. The first bit stream is a collection of multiple data units, or the first bit stream is a collection of sub-PDUs in which multiple data units are located.

[0066] In one possible design, the multiple data units are all data units in a first PDU, and the header of the first PDU includes second information, where the second information is used to indicate that the first PDU or all data units of the first PDU are encrypted.

[0067] In one possible design, the first PDU is located in the first transmission block TB; the multiple data units are all data units in the first PDU; the method also includes: determining the scheduling information of the first TB, the scheduling information includes third information, and the third information is used to indicate that the PDU included in the first TB or all data units in the PDU need to be encrypted.

[0068] In one possible design, the multiple data units are partial data units in a first PDU, and the header of the first PDU includes fourth information, and the fourth information is used to indicate that the multiple data units or the sub-PDU where the multiple data units are located are encrypted.

[0069] In one possible design, when the value corresponding to the first PDU is used to identify the first PDU, the value corresponding to the first PDU is a sequence number SN or a count value COUNT; when the value corresponding to the first PDU is used to indicate the time domain and / or frequency domain position of the first PDU, the value corresponding to the first PDU is any one of the following: the system frame number SFN where the first PDU is located, a value obtained based on the SFN and the super system frame number H-SFN where the first PDU is located, an index of the time domain resource where the first PDU is located, or a value of a time-frequency resource indication field. The value of the time-frequency resource indication field indicates the time-frequency resource used to carry the first PDU.

[0070] In one possible design, the first protocol layer is the media access control MAC layer, and the data unit includes a MAC service data unit SDU or a MAC control element CE.

[0071] Among them, the technical effects brought about by any possible design in the fourth aspect can refer to the technical effects brought about by the corresponding design in the above-mentioned second aspect, and will not be repeated here.

[0072] In a fifth aspect, a communication device is provided for implementing various methods. The communication device includes modules, units, or means corresponding to the implementation method. The modules, units, or means can be implemented through hardware, software, or hardware executing the corresponding software implementation. The hardware or software includes one or more modules or units corresponding to the functions.

[0073] In some possible designs, the communication device may include a processing module and a transceiver module. The processing module may be configured to implement the processing functionality of any of the above aspects and any possible implementations thereof. The transceiver module may include a receiving module and a transmitting module, respectively configured to implement the receiving functionality and the transmitting functionality of any of the above aspects and any possible implementations thereof.

[0074] In some possible designs, the transceiver module may be composed of a transceiver circuit, a transceiver, a transceiver or a communication interface.

[0075] In a sixth aspect, a communication device is provided, comprising: a processor and a memory; the memory is used to store computer instructions, and when the processor executes the instructions, the communication device executes the method described in any one of the aspects.

[0076] In the seventh aspect, a communication device is provided, comprising: a processor and a communication interface; the communication interface is used to communicate with a module outside the communication device; the processor is used to execute a computer program or instruction so that the communication device executes the method described in any aspect.

[0077] In an eighth aspect, a communication device is provided, comprising: at least one processor; the processor is configured to execute a computer program or instruction stored in a memory, so that the communication device performs the method described in any one of the aspects. The memory may be coupled to the processor, or may be independent of the processor.

[0078] In a ninth aspect, a communication device is provided (for example, the communication device may be a chip or a chip system), which includes a processor for implementing the functions involved in any one of the first to sixth aspects.

[0079] In some possible designs, the communication device includes a memory for storing necessary program instructions and data.

[0080] In some possible designs, when the device is a chip system, it can be composed of a chip or include a chip and other discrete devices.

[0081] It can be understood that the communication device provided in the fifth to ninth aspects may be the first communication device in the first or third aspect, or it may be a module or unit (for example, a chip, or a chip system, or a circuit) in the first communication device that corresponds one-to-one to the method / operation / step / action described in the first or third aspect, or it may be a module or unit that can be matched with the first communication device, or it may also be a logical node, logical module or software that can realize all or part of the functions of the first communication device; or, the communication device may be the second or fourth aspect, or it may be a module or unit (for example, a chip, or a chip system, or a circuit) in the second communication device that corresponds one-to-one to the method / operation / step / action described in the second or fourth aspect, or it may be a module or unit that can be matched with the second communication device, or it may also be a logical node, logical module or software that can realize all or part of the functions of the second communication device.

[0082] It can be understood that when the communication device provided in any one of aspects 7 to 9 is a chip, the sending action / function of the communication device can be understood as output information, and the receiving action / function of the communication device can be understood as input information.

[0083] In the tenth aspect, a computer-readable storage medium is provided, which stores a computer program or instruction. When the computer-readable storage medium is run on a communication device, the communication device can execute the method described in any one of the first to sixth aspects.

[0084] In an eleventh aspect, a computer program product comprising instructions is provided, which, when executed on a communication device, enables the communication device to execute the method described in any one of the first to sixth aspects.

[0085] In a twelfth aspect, a communication system is provided, comprising a first communication device and a second communication device. The first communication device is configured to execute the method described in the first or third aspect, and any possible designs thereof, and the second communication device is configured to execute the method described in the second or fourth aspect, and any possible designs thereof.

[0086] Among them, the technical effects brought about by any design method in the fifth to twelfth aspects can refer to the technical effects brought about by different design methods in the first to fourth aspects, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0087] FIG1 is a schematic diagram of the structure of a user plane protocol stack provided by the present application;

[0088] FIG2 is a schematic diagram of the structure of a MAC PDU provided by this application;

[0089] FIG3 is a schematic diagram of a process of a terminal accessing a network provided by the present application;

[0090] FIG4 is a schematic diagram of a process flow of integrity protection / verification provided by this application;

[0091] FIG5 is a schematic diagram of an encryption / decryption process provided by the present application;

[0092] FIG6 is a schematic structural diagram of a pseudo base station provided in this application;

[0093] FIG7 is a schematic diagram of a pseudo base station attack provided by this application;

[0094] FIG8 is a schematic structural diagram of a communication system provided by the present application;

[0095] FIG9 is a flow chart of a data processing method provided by the present application;

[0096] FIG10 is a schematic diagram of a verification code determination process provided by the present application;

[0097] FIG11 is a schematic diagram of another integrity protection / verification process provided by the present application;

[0098] FIG12 is a schematic structural diagram of a sub-header of a sub-PDU provided in this application;

[0099] FIG13 is a schematic diagram of another verification code determination process provided by the present application;

[0100] FIG14 is a schematic diagram of another integrity protection / verification process provided by the present application;

[0101] FIG15 is a flow chart of another data processing method provided by the present application;

[0102] FIG16 is a schematic diagram of another encryption / decryption process provided by the present application;

[0103] FIG17 is a schematic structural diagram of a communication device provided by the present application;

[0104] FIG18 is a schematic structural diagram of another communication device provided by the present application;

[0105] FIG19 is a schematic structural diagram of another communication device provided in this application. DETAILED DESCRIPTION

[0106] In the description of this application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship, for example, A / B can represent A or B; "and / or" in this application is merely a description of the association relationship of associated objects, indicating that three relationships may exist, for example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural.

[0107] In the description of this application, unless otherwise specified, "plurality" means two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0108] In addition, to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, the words "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that the words "first" and "second" do not limit the quantity or execution order, and the words "first" and "second" do not necessarily mean different.

[0109] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner to facilitate understanding.

[0110] It will be understood that the “embodiment” mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, the various embodiments throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It will be understood that in the various embodiments of the present application, the size of the sequence number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present application.

[0111] It can be understood that in this application, "when" and "if" both mean that corresponding processing will be taken under certain objective circumstances, and do not limit the time, nor do they require any judgment action when implementing, nor do they mean that there are other limitations.

[0112] It is understood that some optional features in the embodiments of the present application may, in certain scenarios, be implemented independently of other features, such as the solution on which they are currently based, to solve corresponding technical problems and achieve corresponding effects. They may also be combined with other features in certain scenarios as needed. Accordingly, the devices provided in the embodiments of the present application may also implement these features or functions accordingly, which will not be described in detail here.

[0113] In this application, unless otherwise specified, the same or similar parts between the various embodiments can refer to each other. In the various implementation methods in this application, unless otherwise specified and there is no logical conflict, the terms and / or descriptions between different implementation methods are consistent and can be referenced to each other. The technical features in different implementation methods can be combined to form new embodiments based on their inherent logical relationships. The following description of the implementation methods of this application does not constitute a limitation on the scope of protection of this application.

[0114] In order to facilitate understanding of the technical solutions of the embodiments of the present application, a brief introduction to the relevant technologies of the present application is first given as follows.

[0115] 1. Layered protocol stack architecture:

[0116] In the fifth generation (5G) new radio (NR) communication system, the communication protocol stack architecture of the user plane is shown in Figure 1, which mainly includes the service data adaptation protocol (SDAP) layer (not shown in Figure 1), the packet data convergence protocol (PDCP) layer, the radio link control (RLC) layer, the media access control (MAC) layer, and the physical (PHY) layer.

[0117] In uplink (UL) transmission, data is transmitted in the direction indicated by the arrows in Figure 1. Referring to Figure 1, at the transmitting end, data passes through the SDAP layer and reaches the PDCP layer. After processing at the PDCP layer, data is sequentially transmitted to the RLC layer, the MAC layer, and finally transmitted from the physical layer. At the receiving end, data is processed in the opposite direction to the transmitting end. In downlink (DL) transmission, data is transmitted in the opposite direction of the arrows in Figure 1.

[0118] When the data in the radio bearer (RB) passes through each protocol layer, it needs to be processed by the corresponding functional entity of each protocol layer. For example, it is processed by the PDCP entity at the PDCP layer, by the RLC entity at the RLC layer, and by the MAC entity at the MAC layer.

[0119] Wireless communication data can be broadly divided into control signaling and user plane data. Furthermore, user plane data can be further divided into user plane data protocol data units (PDUs) and user plane control PDUs. User plane data PDUs are used to carry communication data, while user plane control PDUs carry control information that assists the transmission of user plane data PDUs.

[0120] Exemplarily, the user plane data PDU includes data PDUs of various protocol layers, such as SDAP data PDU, PDCP data PDU, RLC data PDU, and MAC sub-PDU including MAC service data unit (SDU). The user plane control PDU includes control PDUs of various protocol layers, such as SDAP control PDU, PDCP control PDU, RLC control PDU, and MAC sub-PDU including MAC control element (CE).

[0121] Taking the MAC layer as an example, as shown in Figure 2, a complete MAC PDU may be composed of a MAC subPDU including a MAC SDU and a MAC subPDU including a MAC CE. Among them, the MAC SDU is the RLC PDU delivered by the RLC layer, and the MAC CE is information generated by the MAC layer.

[0122] In addition, as shown in Figure 2, the MAC subPDU includes a MAC subheader, where R represents a reserved field, F represents the size of the length field in the subheader, L represents the length of the MAC CE or MAC SDU, and LCID represents the logical channel identification (LCID) corresponding to the MAC CE or MAC SDU.

[0123] 2. Air interface security processing:

[0124] Exemplarily, in the NR system, the initial access process of the terminal device is shown in Figure 3. When the terminal device is converted from the radio resource control (RRC) idle (RRC_IDLE) state to the RRC connected (RRC_CONNECTED) state, it needs to complete random access and interact with the access and mobility management function (AMF) network element through the non-access stratum (NAS) message. For example, in step 6, the AMF network element sends the context of the terminal device to the base station, such as the PDU session context, security keys, the wireless capabilities of the terminal device, the security capabilities of the terminal device, etc. After receiving the context of the terminal device, the base station can start the security mode, that is, execute step 7 to send a security mode command to the terminal device.

[0125] After enabling security mode, the terminal device and base station will perform secure data processing. Typically, this includes encryption / decryption and integrity protection / verification. This means the sender encrypts and / or performs integrity protection on the data packet, while the receiver decrypts and / or performs integrity verification on the data packet accordingly.

[0126] 1) Integrity protection / integrity verification:

[0127] The integrity protection and verification process may include: the sender calculates parameter A based on the data packet and parameters such as the key; the receiver calculates parameter B based on the data packet and parameters such as the key. If parameters A and B are consistent, the integrity verification is successful.

[0128] For example, as shown in Figure 4, in the air interface integrity protection mechanism, the transmitter uses regularly changing parameters and data packets to perform calculations based on certain rules to obtain a message authentication code for integrity (MAC-I), and then sends the data packet and MAC-I together to the receiver. The receiver uses the same parameters and the same rules to calculate the expected message authentication code for integrity (XMAC-I), and verifies the MAC-I and XMAC-I to determine whether the received data is complete, thereby achieving the purpose of protecting data integrity.

[0129] 4 , the input parameters for integrity protection and verification include a key (KEY), a count value (COUNT), a message (MESSAGE), a transmission direction (DIRECTION), and a radio bearer identifier (BEARER). Table 1 describes each parameter.

[0130] Table 1

[0131] 2) Encryption / Decryption:

[0132] The encryption and decryption process may include: the sending end converts the data packet into ciphertext through calculation based on parameters such as the key, and the receiving end converts the ciphertext into plaintext through inverse calculation based on parameters such as the key.

[0133] For example, as shown in Figure 5, in the air interface encryption / decryption mechanism, the transmitter generates a key stream (KEYSTREAMBLOCK) based on the input parameters, and then XORs the key stream with the input plaintext (PLAINTEXTBLOCK) to obtain the ciphertext (CIPHERTEXTBLOCK). At the receiver, the same key stream is generated using the same input parameters as the transmitter, and the key stream and ciphertext are XORed to obtain the plaintext. Here, NEA represents the NR encryption algorithm (NEA).

[0134] The input parameters include an encryption key (KEY), a count value (COUNT), a radio bearer identifier (BEARER), a transmission direction (DIRECTION), and a required key stream length (LENGTH).

[0135] 3. Fake base station attack:

[0136] A fake base station is an illegal base station, typically consisting of simple wireless devices and dedicated open-source software. It can simulate a legitimate base station and send signaling to a target terminal according to relevant protocols, thereby obtaining relevant information about the target terminal.

[0137] For example, as shown in Figure 6 or Figure 7 (a), a network attacker can place a fake base station within the coverage area of ​​a target base station, allowing the fake base station to force nearby terminal devices to reselect cells, update locations, and perform handovers, thereby deceiving the terminal devices into providing false information, thereby achieving the purpose of spreading viruses, network fraud, etc. In addition, the fake base station may also intercept the communication content between the base station and the terminal device, thereby monitoring the user's private data.

[0138] At the same time, when a fake base station conducts a deceptive attack on a terminal device, it interferes with the normal communication between the network and the terminal device, affecting network performance. For example, as shown in (b) in Figure 7, when a terminal device accesses a fake base station, it may use an incorrect system message provided by the fake base station, resulting in the terminal device being unable to be paged by the network and thus unable to access the network and operate normally. For another example, the system message may be intercepted and illegally tampered with by the fake base station, causing the terminal device to use incorrect paging parameters, etc., which in turn causes the terminal device to be unable to communicate normally with the legitimate base station, ultimately resulting in handover failure, abnormal call drops, etc.

[0139] Furthermore, as shown in Figure 7 (c), after attracting a terminal device to reside on a fake base station, the fake base station can also use the malicious terminal to "relay" encrypted data between the legitimate terminal and the base station. For example, in the uplink, the fake base station receives communication data from the legitimate terminal and transparently transmits it to the legitimate base station via the malicious terminal; in the downlink, the malicious terminal receives communication data from the legitimate base station and transparently transmits it to the legitimate terminal via the fake base station. In this scenario, the legitimate terminal and the legitimate base station are difficult to detect the presence of the fake base station and malicious terminal, making it possible for the fake base station or malicious terminal to carry out a man-in-the-middle attack.

[0140] Currently, this security processing is performed at the PDCP layer and is limited to user-plane PDUs within the PDCP layer. No security processing is performed on other user-plane PDUs. However, many user-plane PDUs other than data PDUs may carry important control information. If exploited by rogue base stations or unauthorized terminals to forge or monitor these PDUs, this poses a significant security risk. For example, a rogue base station could implement a man-in-the-middle attack, transparently transmitting upper-layer encrypted data while tampering with or forging underlying signaling, or attacking by dropping packets, thereby impacting the user experience.

[0141] Based on this, the present application provides a data processing method that can perform integrity protection on data units in the lower protocol layers of the PDCP layer, enabling a receiving end to verify the integrity of the data units, thereby identifying whether a man-in-the-middle attack exists and taking appropriate measures to improve the user's service experience. In addition, the result of integrity protection for multiple data units can be a verification code (i.e., a first verification code), which can reduce signaling overhead compared to corresponding verification codes for each data unit.

[0142] The technical solutions of the embodiments of the present application can be used in various communication systems, which may be third generation partnership project (3GPP) communication systems, such as fourth generation (4G) systems such as long term evolution (LTE) systems, 5G systems such as NR systems, systems of hybrid LTE and 5G networking, non-terrestrial networks (NTN), or other next generation communication systems. The communication system may also be a non-3GPP communication system without limitation.

[0143] Among them, the above-mentioned communication system applicable to this application is only an example, and the communication system applicable to this application is not limited to this. The communication system provided by this application does not impose any limitations on the solution of this application. It is uniformly explained here and will not be repeated below.

[0144] Figure 8 shows a possible, non-limiting system diagram. As shown in Figure 8, communication system 80 includes a radio access network (RAN) 800 and a core network (CN) 900. RAN 800 includes at least one RAN node (such as 810a and 810b in Figure 8, collectively referred to as 810) and at least one terminal (820a-820j in Figure 8, collectively referred to as 820). RAN 800 may also include other RAN nodes, such as wireless relay equipment and / or wireless backhaul equipment (not shown in Figure 8). Terminal 820 is wirelessly connected to RAN node 810. RAN node 810 is wirelessly or wiredly connected to core network 900. The core network equipment in core network 900 and RAN node 810 in RAN 800 can be different physical devices, or they can be the same physical device that integrates core network logical functions and radio access network logical functions.

[0145] The RAN 800 may be a 3GPP-related cellular system, such as a 4G or 5G mobile communication system, or a future-oriented evolutionary system (such as a sixth generation (6G) mobile communication system). The RAN 800 may also be an open access network (O-RAN or ORAN), a cloud radio access network (CRAN), or a wireless fidelity (WiFi) system. The RAN 800 may also be a communication system that integrates two or more of the above systems.

[0146] The RAN node 810, which may also sometimes be referred to as access network equipment, RAN entity or access node, etc., constitutes a part of the communication system to help terminals achieve wireless access. The multiple RAN nodes 810 in the communication system 80 may be nodes of the same type or nodes of different types. In some scenarios, the roles of the RAN node 810 and the terminal 820 are relative. For example, the network element 820i in Figure 8 may be a helicopter or a drone, which may be configured as a mobile base station. For the terminal 820j that accesses the RAN 800 through the network element 820i, the network element 820i is a base station; but for the base station 810a, the network element 820i is a terminal. The RAN node 810 and the terminal 820 are sometimes referred to as communication devices. For example, the network elements 810a and 810b in Figure 8 may be understood as communication devices with base station functions, and the network elements 820a-820j may be understood as communication devices with terminal functions.

[0147] In one possible scenario, a RAN node may be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next generation NodeB (gNB), a next generation base station in a sixth generation (6G) mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system. A RAN node may be a macro base station (such as 810a in FIG8 ), a micro base station or an indoor station (such as 810b in FIG8 ), a relay node or a donor node, or a wireless controller in a CRAN scenario. Optionally, a RAN node may also be a server, a wearable device, a vehicle or an onboard device. For example, an access network device in vehicle to everything (V2X) technology may be a road side unit (RSU). All or part of the functions of the RAN node in this application may also be implemented by software functions running on hardware, or by virtualized functions instantiated on a platform (such as a cloud platform). The RAN node in this application may also be a logical node, a logical module or software that can implement all or part of the RAN node functions.

[0148] In another possible scenario, multiple RAN nodes collaborate to assist the terminal in achieving wireless access, and different RAN nodes respectively implement part of the functions of the base station. For example, the RAN node can be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be set separately, or they can be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).

[0149] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, CU may also be called O-CU (Open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application uses CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0150] A terminal can be a user-side device with wireless transceiver capabilities, or it can be a chip or chip system installed in the device. A terminal can also be called user equipment (UE), terminal equipment, access terminal, subscriber unit, subscriber station, mobile station (MS), mobile station, remote station, remote terminal, mobile terminal (MT), user terminal, wireless communication device, user agent, or user device.

[0151] The terminal can be widely used in various scenarios, for example, device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), Internet of Things (IOT), virtual reality (VR), augmented reality, industrial control, self-driving, remote medical, smart grid, smart furniture, smart office, smart wearable, smart transportation, smart home, transportation safety, smart city, etc. The terminal can be a mobile phone, a tablet computer, a computer with wireless transceiver function, a wearable device, a vehicle, a drone, a helicopter, an airplane, a ship, a robot, a robotic arm, a smart home device, a vehicle-mounted terminal, a drone, etc. The embodiments of the present application do not limit the device form of the terminal.

[0152] It should be noted that the communication system described in the embodiment of the present application is intended to more clearly illustrate the technical solution of the embodiment of the present application, and does not constitute a limitation on the technical solution provided in the embodiment of the present application. Ordinary technicians in this field can know that with the evolution of network architecture and the emergence of new business scenarios, the technical solution provided in the embodiment of the present application is also applicable to similar technical problems.

[0153] The data processing method provided in the embodiment of the present application is described below in conjunction with the communication system shown in Figure 8. It should be noted that in the following embodiments of the present application, the message names, names of various parameters, or names of various information between communication devices are merely examples, and other names may also be used in other embodiments, and the method provided in the present application does not specifically limit this.

[0154] It is understood that in the embodiments of the present application, the communication device may perform some or all of the steps in the embodiments of the present application. These steps or operations are merely examples, and the embodiments of the present application may also perform other operations or variations of various operations. In addition, the various steps may be performed in a different order than those presented in the embodiments of the present application, and it is possible that not all operations in the embodiments of the present application need to be performed.

[0155] 9 is a flowchart of a data processing method provided in an embodiment of the present application. As shown in FIG9 , the data processing method may include the following steps:

[0156] S901. A first communication device determines a plurality of data units of a first protocol layer.

[0157] Exemplarily, the first communication device can be understood as a transmitting end. The first communication device can be a terminal in the communication system shown in Figure 8, or a component of the terminal (such as a processor, circuit, chip, or chip system), or a logic module or software that can implement all or part of the terminal functions; or the first communication device can be a RAN node in the communication system shown in Figure 8, or a component of the RAN node (such as a processor, circuit, chip, or chip system), or a logic module or software that can implement all or part of the RAN node functions.

[0158] The first protocol layer is a lower protocol layer of the PDCP layer. Exemplarily, the first protocol layer provides at least one of the following functions:

[0159] 1) Mapping between logical channels and transport channels;

[0160] 2) Multiplexing the first protocol layer SDUs belonging to one or different logical channels into the physical layer transport block (TB) on the transport channel for transmission, or demultiplexing the first protocol layer SDUs belonging to one or different logical channels that were input from the physical layer TB on the transport channel;

[0161] 3) Dispatch information report;

[0162] 4) Error correction through hybrid automatic repeat request (HARQ);

[0163] 5) Handling priorities between terminals through dynamic scheduling;

[0164] 6) Processing the priority between logical channels of a terminal through logical channel priority;

[0165] 7) Prioritize overlapping resources of a terminal;

[0166] 8) Data filling.

[0167] Exemplarily, the first protocol layer that provides at least one of the above eight functions may be called a MAC layer. Accordingly, the data unit of the first protocol layer may be a MAC CE or a MAC SDU. In addition, the MAC layer may also have other names, and this application does not specifically limit the name of the MAC layer.

[0168] In addition to the MAC layer, the first protocol layer may also be other protocol layers below the PDCP layer, such as the RLC layer, etc. This application does not specifically limit the first protocol layer.

[0169] In one possible implementation, the multiple data units may be understood as data units requiring integrity protection. Exemplarily, there may be various schemes for implementing integrity protection, such as a MAC-I-based integrity protection scheme (see the integrity protection mechanism of the PDCP layer described above), digital signature-based integrity protection, cyclic redundancy check (CRC)-based integrity protection, or hash function-based integrity protection.

[0170] For example, a MAC-I-based integrity protection scheme can be understood as a keyed HASH function-based integrity protection scheme, which can not only protect integrity but also protect data authenticity. A CRC scheme is suitable for situations with small amounts of data. A hash function scheme is suitable for situations with larger amounts of data. The following embodiments of this application illustrate MAC-I-based integrity protection of data units.

[0171] As a possible implementation, when a data unit of the first protocol layer is a PDU of an upper protocol layer of the first protocol layer (called the second protocol layer), such as a MAC SDU, when an entity of the second protocol layer delivers the data unit to an entity of the first protocol layer, it can send indication information to the entity of the first protocol layer to indicate that the data unit needs to be integrity protected.

[0172] As another possible implementation, when a data unit of the first protocol layer is a data unit generated by an entity of the first protocol layer, such as a MAC CE, the first protocol layer may determine whether the data unit requires integrity protection based on the implementation. For example, if the data unit carries information with a high level of importance, a high security risk, or a high security requirement, then the data unit requires integrity protection; if the data unit carries information with a low level of importance, a low security risk, or a low security requirement, then the data unit does not require integrity protection.

[0173] As another possible implementation, the protocol may predefine or the RAN node may preconfigure at least one LCID or at least one logical channel group (LCG) identifier, and the data unit corresponding to the at least one LCID or LCG identifier is the data unit that requires integrity protection. In this scenario, the first communication device may determine the above-mentioned multiple data units based on the at least one LCID or LCG identifier.

[0174] Exemplarily, the first communication device may first determine the LCID or LCG identifier of the data unit. If the LCID of the data unit belongs to the at least one LCID mentioned above, and / or the LCG identifier of the data unit belongs to the at least one LCG identifier mentioned above, then the data unit needs to be integrity protected. In other words, the at least one LCID includes the LCID of each data unit in the multiple data units, or the at least one LCG identifier includes the LCG identifier of each data unit in the multiple data units.

[0175] For example, when a data unit of the first protocol layer is a PDU of the second protocol layer, the first protocol layer is the MAC layer, and the second protocol layer is the RLC layer, the LCID of the data unit is the identifier of the logical channel used when the entity of the RLC layer delivers the data unit to the entity of the MAC layer. In other words, the LCID of the data unit is the identifier of the logical channel for transmitting the data unit between the RLC layer entity and the MAC layer entity.

[0176] In the case where a data unit of the first protocol layer is a data unit generated by an entity of the first protocol layer, such as a MAC CE, the LCID of the data unit may be determined based on the type or function of the data unit. For example, taking the data unit as a MAC CE, the type of MAC CE may include, but is not limited to, a buffer status report (BSR), a discontinuous reception (DRX) command, a UE contention resolution identity, a timing advance (TA) command, etc. Different types of MAC CEs have different LCIDs.

[0177] Optionally, in the case where the above-mentioned at least one LCID or at least one LCG identifier is configured for a RAN node, if the first communication device is a terminal, the terminal receives information from the RAN node for indicating the at least one LCID or LCG identifier; if the first communication device is a RAN node, the first communication device sends information to the terminal for indicating the at least one LCID or LCG identifier.

[0178] Exemplarily, the information indicating the at least one LCID or LCG identifier may be carried in broadcast information, system information or RRC signaling, which is not specifically limited in this application.

[0179] S902: The first communication device determines a first verification code.

[0180] The first verification code is used to verify the integrity of the multiple data units, or in other words, the first verification code is used to protect the integrity of the multiple data units.

[0181] It should be noted that the verification code in the embodiment of the present application may also be called MAC-I, integrity verification code, integrity authentication code, integrity authentication code, verification information, etc. Of course, the verification code may also have other names, and the present application does not specifically limit the name of the verification code.

[0182] Optionally, the length of the first verification code is variable, or the length of the first verification code may have multiple values. The specific length can be predefined by the protocol, or the first communication device can indicate the length of the first verification code to the receiving end, or it can be pre-negotiated by the first communication device and the receiving end.

[0183] In a possible implementation, the first communication device determines the first verification code based on the multiple data units. The specific implementation will be described in detail in subsequent embodiments and will not be repeated here.

[0184] S903: The first communication device outputs a first PDU. Correspondingly, the second communication device receives the first PDU, wherein the first PDU includes the aforementioned multiple data units and the first verification code.

[0185] Exemplarily, the second communication device can be understood as a receiving end. The second communication device can be a RAN node in the communication system shown in Figure 8, or a component of a RAN node (such as a processor, circuit, chip, or chip system), or a logic module or software that can implement all or part of the RAN node functions; or the second communication device can be a terminal in the communication system shown in Figure 8, or a component of a terminal (such as a processor, circuit, chip, or chip system), or a logic module or software that can implement all or part of the terminal functions.

[0186] It can be understood that the first PDU is a PDU of the first protocol layer. Exemplarily, when the first protocol layer is the MAC layer, the first PDU can also be called a first transport block (TB).

[0187] Optionally, the aforementioned multiple data units may be part or all of the data units of the first PDU. That is, in addition to the aforementioned multiple data units, the first PDU may or may not include other data units. If the first PDU also includes other data units, these other data units may be understood as data units that are not integrity protected.

[0188] In one possible implementation, the first communication device outputting the first PDU may include: the first communication device sending the first PDU to the second communication device. The second communication device receiving the first PDU may include: the second communication device receiving the first PDU from the first communication device. In this case, the output action may be implemented by a radio frequency device (e.g., a radio frequency chip) of the first communication device.

[0189] In another possible implementation, the first communication device outputting the first PDU may include: a first protocol layer entity of the first communication device delivering the first PDU to a third protocol layer entity of the first communication device. The third protocol layer entity is an entity of a lower protocol layer (e.g., a physical layer) of the first protocol layer. In this case, the output action may be implemented by a baseband device (e.g., a baseband chip) of the first communication device.

[0190] S904: The second communication device determines a second verification code.

[0191] The second verification code is used to verify the integrity of the plurality of data units. Exemplarily, the second verification code is used to verify the integrity of the plurality of data units in the first PDU received by the second communication device.

[0192] In a possible implementation, the second communication device determines the second verification code based on the multiple data units in the received first PDU. The specific implementation will be described in detail in subsequent embodiments and will not be repeated here.

[0193] S905: The second communication device determines whether the multiple data units have been changed based on the first verification code and the second verification code. The multiple data units may be changed due to transmission errors or malicious changes.

[0194] In a possible implementation, if the first verification code and the second verification code are the same, it indicates that the multiple data units have not been changed; if the first verification code and the second verification code are different, it indicates that the multiple data units have been changed.

[0195] In a possible implementation, when the second communication device determines that the multiple data units are changed, the second communication device may discard the multiple data units and request the first communication device to retransmit.

[0196] Optionally, in a CU and DU separation architecture, the above-mentioned RAN node may be a DU, that is, the functions of the RAN node in the embodiment of the present application may be implemented by the DU.

[0197] Based on the above scheme, the transmitting end can perform integrity protection on the data units of the first protocol layer, because the first protocol layer is usually located below the PDCP layer, or is usually a relatively low-level protocol layer. Therefore, the scheme of the present application performs integrity protection on the data units of the low-level protocol layer, so that the receiving end can verify the integrity of the data units of the low-level protocol layer, thereby identifying whether there is a malicious attack, and then taking corresponding measures to improve the user's service experience. Since the PDU of the high-level protocol layer is usually used as the data unit of the low-level protocol layer, it can be considered that the scheme of the present application performs integrity protection on the PDU of the high-level protocol layer (including user plane PDU and control plane PDU) at the first protocol layer, thereby preventing fake base stations or illegal terminals from using these PDUs, thereby improving the security performance of data transmission. In addition, the result of integrity protection of multiple data units is a verification code (i.e., the first verification code), which can reduce signaling overhead compared to each data unit corresponding to a verification code.

[0198] The above describes the overall process of the data processing method provided by this application. The following describes the specific implementation of the first communication device determining the first verification code in step 902 and the second communication device determining the second verification code in step S904. For example, the first communication device can determine the first verification code in the following two ways:

[0199] Method 1: The first communication device determines verification codes corresponding to the plurality of data units, and then determines a first verification code based on the verification codes corresponding to the plurality of data units.

[0200] Exemplarily, the verification codes corresponding to the multiple data units can be referred to as sub-verification codes (e.g., denoted as sub MAC-I). Taking the multiple data units as data unit 1, data unit 2, and data unit 3 as an example, the first communication device first determines the verification codes corresponding to the three data units (denoted as sub-verification code 1, sub-verification code 2, and sub-verification code 3), respectively, and then determines the first verification code based on sub-verification code 1, sub-verification code 2, and sub-verification code 3.

[0201] Exemplarily, as shown in Figure 10, taking the first protocol layer as the MAC layer, and the multiple data units including MAC CE 1, MAC CE 2 and MAC SDU N as an example, the first communication device can first determine sub MAC-I 1 corresponding to MAC CE 1, sub MAC-I 2 corresponding to MAC CE 2, and MAC-I 3 corresponding to MAC SDU N, and then determine the first verification code (represented by MAC-I in Figure 10) based on sub MAC-I 1, sub MAC-I 2 and sub MAC-I 3.

[0202] As a possible implementation, taking multiple data units including a first data unit as an example, the verification code corresponding to the first data unit is obtained based on the first data unit and at least one of the following items, or in other words, the input parameters for integrity protection of the first data unit include the first data unit and at least one of the following items: a key (or called an integrity protection key), a numerical value corresponding to the first PDU, a transmission direction of the first PDU, a HARQ identifier corresponding to the first PDU, an LCID corresponding to the first data unit, a wireless bearer identifier corresponding to the first data unit, or a type parameter of the first data unit.

[0203] Exemplarily, the terminal can obtain the integrity protection key from the USIM. The RAN node can calculate the integrity protection key using the root key. The root key can be stored in the UDM network element or other core network elements, without limitation.

[0204] Exemplarily, the numerical value corresponding to the first PDU is used to identify the first PDU or to indicate the time domain and / or frequency domain position of the first PDU. For example, the numerical value corresponding to the first PDU is any one of the following: a sequence number (SN), a count value (COUNT), a system frame number (SFN) where the first PDU is located, a value obtained based on the SFN where the first PDU is located and a hyper system frame number (H-SFN), an index of the time domain resource where the first PDU is located, or a value of a time-frequency resource indication field.

[0205] The SN and / or count value corresponding to the first PDU can be used to identify the first PDU. In addition, the SN and / or count value corresponding to the first PDU can be carried in the header of the first PDU or the sub-header of the sub-PDU and output, so that the second communication device can determine the second verification code and perform integrity verification.

[0206] The SFN, H-SFN, index of time domain resources and the value of the time-frequency resource indication field where the first PDU is located can be used to indicate the time domain and / or frequency domain position where the first PDU is located. It can be obtained through the scheduling information of the TB where the first PDU is located (such as downlink control information (DCI)). The value obtained based on the SFN and H-SFN where the first PDU is located can be a cascade of the SFN and H-SFN. The index of the time domain resource where the first PDU is located can be an index of orthogonal frequency division multiplexing (OFDM) or an index of a time slot, etc., without limitation. The value of the time-frequency resource indication field indicates the time-frequency resource used to carry the first PDU.

[0207] Exemplarily, the transmission direction of the first PDU may also be replaced by the transmission direction of the first data unit, and the two are consistent. The transmission direction includes uplink or downlink.

[0208] Exemplarily, the HARQ identifier corresponding to the first PDU may also be understood as an identifier of the HARQ process corresponding to the first PDU, or a number (HARQ process number) of the HARQ process corresponding to the first PDU.

[0209] Exemplarily, the LCID corresponding to the first data unit may be an identifier of a logical channel for transmitting the data unit between an RLC layer entity and a MAC layer entity. Alternatively, the LCID corresponding to the first data unit may be determined based on the type or function of the data unit. For details regarding the LCID in step S901 above, no further details are given here.

[0210] Exemplarily, the identifier of the radio bearer corresponding to the first data unit may be the identifier of the radio bearer that carries the first data unit.

[0211] Exemplarily, the type parameter of the first data unit can be a numerical value, and different numerical values ​​represent different types of the first data unit. For example, when the first protocol layer is the MAC layer, the data packet submitted by the RLC layer to the MAC layer includes data, PDCP status report or RLC control PDU, and the logical channels of the data, PDCP status report and RLC control PDU submitted by the RLC are the same, that is, the LCIDs corresponding to the three are the same. In this scenario, a type parameter is needed to distinguish the three. That is, in this example, the first data unit may be data or PDCP status report or RLC control PDU.

[0212] For example, taking the example that the verification code corresponding to the first data unit is obtained based on the key, the numerical value corresponding to the first PDU, the first data unit, the transmission direction of the first PDU and the LCID corresponding to the first data unit, the schematic diagram of the first communication device determining the verification code corresponding to the first data can be shown in Figure 11.

[0213] It is understandable that the first data unit is any one of the above-mentioned multiple data units. That is, the implementation of the verification code corresponding to each of the above-mentioned multiple data units can refer to the implementation of the verification code corresponding to the first data unit.

[0214] As a possible implementation, the first verification code is the exclusive OR of the verification codes corresponding to the multiple data units. For example, based on the example shown in Figure 10, the first verification code is the exclusive OR of sub MAC-I 1, sub MAC-I 2 and sub MAC-I 3.

[0215] As another possible implementation, the first verification code is a verification code obtained by performing integrity protection on verification codes corresponding to multiple data units.

[0216] For example, verification codes corresponding to the plurality of data units may be used as input parameters, and the first verification code may be obtained by operating the integrity protection algorithm. Furthermore, the input parameter may further include at least one of an integrity protection key, a transmission direction of the first PDU, a HARQ identifier corresponding to the first PDU, or a value corresponding to the first PDU. For details, please refer to the above description and will not be repeated here.

[0217] For another example, the first verification code is a CRC check value of a set of verification codes corresponding to the above-mentioned multiple data units. The set can be, for example, a bit stream obtained by concatenating (or serially concatenating) the verification codes corresponding to the multiple data units in a specific order. The specific order can be the order of the multiple data units from front to back or from back to front in the first PDU, and of course other orders are also possible and are not limited.

[0218] For example, if the length of the set (the number of bits in the set) is K and the length of the CRC check value of the set is R, the first communication device can add R zeros after the K bits of data in the set to obtain K+R bits of data. The CRC check value is then determined based on the K+R bits of data and a CRC generator polynomial. The number of bits P of binary symbols in the CRC generator polynomial is equal to R+1. The CRC generator polynomial can be pre-agreed upon by the first and second communication devices.

[0219] The process of the first communication device determining the CRC check value based on the K+R bits of data and the CRC generator polynomial may include: performing a modulo-2 division operation, that is, dividing the K+R bits of data by the binary code element of the CRC generator polynomial to obtain a remainder. Then, determining whether the order of the remainder is less than R. The order of the remainder is equal to the length of the binary representation of the remainder minus 1. If the order of the remainder is less than R, the remainder is the CRC check code (if the length of the binary representation of the remainder is less than R, 0 is added to the front of the remainder to pad it to R bits); if the order of the remainder is greater than or equal to R, the remainder is continued to be divided by the binary code element of the CRC generator polynomial until the order of the remainder is less than 0.

[0220] Optionally, the data unit may be located in a sub-PDU (subPDU) included in the first PDU. In the sub-header of the sub-PDU, the first communication device may indicate whether the data unit in the sub-PDU is integrity protected, or indicate whether the verification object of the first verification code includes the data unit in the sub-PDU.

[0221] In the case where the multiple data units include the first data unit, the first PDU may include a first sub-PDU, and the first data unit may be located in the first sub-PDU. Furthermore, the subheader of the first sub-PDU may include first information, the first information being used to indicate that integrity protection is performed on the first data unit, or the first information being used to indicate that an object of verification of the first verification code includes the first data unit.

[0222] For example, the first information may be located in a reserved field in the subheader of the first sub-PDU, or a new field may be added to the subheader of the first sub-PDU to carry the first information. The field carrying the first information may be called a security indication field, but other names are also possible and are not limited thereto.

[0223] Exemplarily, the field carrying the first information may be 1 bit. When the value of this 1 bit is a first value, it represents the first information, indicating that integrity protection is performed on the first data unit; when the value of this 1 bit is a second value, it indicates that integrity protection is not performed on the first data unit. For example, the first value may be "1", and the corresponding second value may be "0"; or, alternatively, the first value may be "0", and the corresponding second value may be "1".

[0224] For example, when the first protocol layer is the MAC layer, the subheader structure of the sub-PDU in the first PDU can be as shown in (a) or (b) in Figure 12. R represents a reserved field, and the LCID field is used to carry the LCID corresponding to the data unit. F represents the size of the length field in the subheader, and L represents the length field, which is used to carry the length of the data unit. Based on the example shown in Figure 12, the first information can be located in the reserved field.

[0225] Based on this design, the sending end can indicate which data units are integrity protected, so that the receiving end can clearly identify the data units that need to be integrity verified, thereby determining the second verification code based on the correct data units and improving the accuracy of the integrity verification.

[0226] Optionally, as a possible implementation, the first verification code may be located in a second sub-PDU included in the first PDU. The second sub-PDU may be the last sub-PDU in the first PDU.

[0227] Exemplarily, the subheader of the second sub-PDU may include the length information of the first verification code. Alternatively, the length of the first verification code may be agreed upon in the protocol or pre-negotiated between the transmitting end and the receiving end. In this case, the subheader of the second sub-PDU may not include the length information of the first verification code.

[0228] As another possible implementation, the first verification code can be carried at the end of the first PDU, for example, at the beginning of the padding portion of the first PDU (as shown in FIG10 ). That is, the first verification code may not be carried in the sub-PDU. In this case, the length of the first verification code may be agreed upon by the protocol or pre-negotiated between the sender and the receiver.

[0229] Based on the first approach, the first communication device first determines the verification codes corresponding to the multiple data units and then determines the first verification code based on the verification codes corresponding to the multiple data units. Therefore, integrity protection can be performed immediately after the first communication device obtains the data unit. This eliminates the need to wait for the first protocol layer entity to complete assembly of the first PDU before performing integrity protection, reducing data processing latency and improving service performance.

[0230] For example, taking the MAC layer as the first protocol layer, data in the logical channel is typically multiplexed at the MAC layer, i.e., multiplexed into a TB and then delivered to the lower protocol layer via the transport channel. As shown in FIG13 , based on the above-described first approach, after the first communication device obtains a data unit from the logical channel, it can immediately determine the verification code corresponding to the data unit (denoted as sub MAC-I), thereby determining the first verification code (denoted as MAC-I), and subsequently encapsulate the first verification code during multiplexing.

[0231] Among them, the logical channels shown in Figure 13 are, from left to right: multicast control channel (MCCH), multicast traffic channel (MTCH), paging control channel (PCCH), broadcast control channel (BCCH), common control channel (CCCH), dedicated control channel (DCCH), and dedicated traffic channel (DTCH).

[0232] The transmission channels shown in Figure 13 are, from left to right: paging channel (PCH), broadcast channel (BCH), downlink shared channel (DL-SCH), uplink shared channel (UL-SCH), and random access channel (RACH).

[0233] Method 2: The first communication device determines a first input parameter and determines a first verification code based on the first input parameter. The first input parameter includes a first bit stream and at least one of the following: a key (or integrity protection key), a value corresponding to the first PDU, a transmission direction of the first PDU, or a HARQ identifier corresponding to the first PDU.

[0234] Exemplarily, taking the example that the first verification code is obtained based on the key, the value corresponding to the first PDU, the first bit stream and the transmission direction of the first PDU, the schematic diagram of the first communication device determining the first verification code can be shown in Figure 14.

[0235] As a first possible implementation, the first bit stream is a collection of the aforementioned multiple data units. Exemplarily, the first bit stream is a bit stream obtained by concatenating (or serially connecting) the multiple data units in a specific order. The specific order can be the order of the multiple data units from front to back or from back to front in the first PDU, and of course other orders are also possible and are not limited.

[0236] Exemplarily, when the multiple data units are partial data units of the first PDU, based on the example shown in FIG10 , the first bit stream may be expressed as: MAC CE 1||MAC CE 2||MAC SDU N, where “||” indicates concatenation.

[0237] Exemplarily, in the case where the multiple data units are all data units of the first PDU, assuming that the first PDU includes MAC CE 1, MAC CE 2, MAC SDU 1, MAC SDU 2,…, MAC SDU N, the first bit stream can be expressed as MAC CE 1||MAC CE 2||MAC SDU 1||MAC SDU 2||…||MAC SDU N.

[0238] As a second possible implementation, the first bit stream is a collection of sub-PDUs (denoted as multiple sub-PDUs) containing the multiple data units. Exemplarily, the first bit stream is a bit stream obtained by concatenating (or serially connecting) the multiple sub-PDUs in a specific order. The specific order can be the order of the multiple sub-PDUs from front to back or from back to front in the first PDU, and other orders are also possible and are not limited to this order.

[0239] Exemplarily, when the multiple data units are partial data units of the first PDU, that is, the multiple sub-PDUs are partial sub-PDUs of the first PDU, based on the example shown in FIG10 , the first bit stream can be expressed as: subPDU including MAC CE 1||subPDU including MAC CE 2||subPDU including MAC SDU N. Wherein, “||” indicates cascading.

[0240] Exemplarily, when the multiple data units are all data units of the first PDU, that is, the multiple sub-PDUs are all sub-PDUs of the first PDU, assuming that the first PDU includes MAC CE 1, MAC CE 2, MAC SDU 1, MAC SDU 2,…, MAC SDU N, the first bit stream can be expressed as subPDU including MAC CE 1||subPDU including MAC CE 2||subPDU including MAC SDU 1||subPDU including MAC SDU 2||…||subPDU including MAC SDU N.

[0241] It can be understood that, compared with the first possible implementation, the second possible implementation also performs integrity protection on the sub-header of the sub-PDU.

[0242] Exemplarily, determining the first verification code based on the first input parameter may include: using the first input parameter as an input of an integrity protection algorithm, where the output of the integrity protection algorithm is the first verification code.

[0243] Among them, other parameters used to determine the first verification code except the first bit stream can refer to the relevant description in the above-mentioned method 1, and will not be repeated here.

[0244] In one possible embodiment, when the above-mentioned multiple data units are all data units of the first PDU, the header of the first PDU may include second information, which can be used to indicate that integrity protection is performed on the first PDU (or all sub-PDUs of the first PDU) or all data units of the first PDU.

[0245] Exemplarily, the second information may be a 1-bit indicator. When the value of the 1-bit is a first value, the second information indicates that integrity protection is performed on the first PDU; when the value of the 1-bit is a second value, it indicates that integrity protection is performed on all data units of the first PDU. The first value may be, for example, "1," and the corresponding second value is "0," or alternatively, the first value may be "0," and the corresponding second value is "1."

[0246] In another possible embodiment, when the above-mentioned multiple data units are all data units of the first PDU, the first PDU is located in the first TB or the first PDU is the first TB, the first communication device also determines the scheduling information of the first TB, and the scheduling information may include third information, and the third information is used to indicate that the PDU included in the first TB or all data units in the PDU need to be integrity protected. The first communication device can learn based on the third information that the first PDU (or all sub-PDUs of the first PDU) or all data units of the first PDU need to be integrity protected. At the receiving end, the second communication device can also learn based on the third information that the first communication device has performed integrity protection on the first PDU or all data units of the first PDU. For the implementation of the third information, please refer to the relevant description of the above-mentioned second information and will not be repeated here.

[0247] When the first communication device is a terminal and the second communication device is a RAN node, the first communication device determining the scheduling information for the first TB may include: the first communication device receiving the scheduling information for the first TB from the second communication device. When the first communication device is a RAN node and the second communication device is a terminal, the first communication device further transmits the scheduling information for the first TB to the second communication device. Exemplarily, the RAN node may transmit the scheduling information for the first TB to the terminal by including it in a DCI.

[0248] In another possible implementation, when the multiple data units are part of the data units in the first PDU, the header of the first PDU may include fourth information indicating that integrity protection is performed on the multiple data units or the sub-PDUs in which the multiple data units are located.

[0249] For example, the fourth information may include indication information and a bit map. The indication information indicates the data unit or the sub-PDU where the data unit is located. The bit map may include M bits, where M is the total number of data units in the first PDU, and the M bits correspond one-to-one to the M data units or M sub-PDUs (i.e., the sub-PDU where the M data units are located) in the first PDU. When the value of the first bit is a preset value, it indicates that the data unit or sub-PDU corresponding to the first bit is integrity protected. Specifically, whether the data unit or sub-PDU corresponding to the first bit is integrity protected can be determined by the indication information. When the indication information indicates the data unit, it indicates that the data unit corresponding to the first bit is integrity protected; when the indication information indicates the sub-PDU, it indicates that the sub-PDU corresponding to the first bit is integrity protected. The first bit is any one of the M bits.

[0250] For another example, the fourth information may include indication information and the numbers of the multiple data units or multiple sub-PDUs in the first PDU, indicating that integrity protection is performed on the data units or sub-PDUs corresponding to these numbers. Whether integrity protection is performed on the data units or sub-PDUs can be determined through the indication information. Please refer to the above-mentioned relevant instructions and will not be repeated here.

[0251] Based on the second approach described above, the integrity protection algorithm only needs to be calculated once during the process of determining the first verification code, which can reduce computational overhead. In addition, when the first bit stream is a collection of sub-PDUs containing the above-mentioned multiple data units, the sub-headers corresponding to the multiple data units are also integrity protected, which can further improve security performance.

[0252] Exemplarily, the second communication device may determine the second verification code in the following two ways:

[0253] Method A: The second communication device determines verification codes corresponding to multiple data units, and then determines a second verification code based on the verification codes corresponding to the multiple data units. It can be understood that the multiple data units are multiple data units in the first PDU received by the second communication device.

[0254] As one possible implementation, the second verification code is the exclusive OR of the verification codes corresponding to the multiple data units. Alternatively, the second verification code is the verification code obtained by integrity protection of the verification codes corresponding to the multiple data units. For example, the second verification code can be obtained by using the verification codes corresponding to the multiple data units as input parameters and computing the second verification code through an integrity protection algorithm. Alternatively, the second verification code is the set of verification codes corresponding to the multiple data units. Please refer to the relevant description of Method 1 above and will not be repeated here.

[0255] As a possible implementation, taking multiple data units including a first data unit as an example, the verification code corresponding to the first data unit is obtained based on at least one of the following items, or in other words, the input parameters for integrity protection of the first data unit include at least one of the following items: a key (or called an integrity protection key), a first data unit, a numerical value corresponding to the first PDU, a transmission direction of the first PDU, a HARQ identifier corresponding to the first PDU, an LCID corresponding to the first data unit, a wireless bearer identifier corresponding to the first data unit, or a type parameter of the first data unit.

[0256] For example, taking the example where the verification code corresponding to the first data unit is obtained based on the key, the numerical value corresponding to the first PDU, the first data unit, the transmission direction of the first PDU, and the LCID corresponding to the first data unit, the schematic diagram of the second communication device determining the verification code corresponding to the first data can be shown in Figure 11.

[0257] As a possible implementation, if the first communication device indicates in the subheader of the sub-PDU whether integrity protection is performed on the data units in the sub-PDU, the second communication device can determine the multiple data units based on the indication. That is, the multiple data units are the data units in the first PDU that have been integrity protected.

[0258] As another possible implementation, the second communication device can determine at least one LCID or at least one LCG identifier, and the data unit corresponding to the at least one LCID or LCG identifier is the data unit that needs to be integrity protected. In this scenario, the second communication device can determine the above-mentioned multiple data units based on the at least one LCID or LCG identifier. For example, if the LCID of a data unit belongs to the at least one LCID mentioned above, and / or the LCG identifier of the data unit belongs to the at least one LCG identifier mentioned above, it means that the data unit is a data unit that has been integrity protected.

[0259] The specific implementation of method A can refer to the description of method 1 above, which will not be repeated here. It can be understood that when the first communication device determines the first verification code through method 1 above, the second communication device determines the second verification code through method A.

[0260] Exemplarily, when the second verification code is a set of verification codes corresponding to multiple data units, in step S905, the second communication device determining whether the multiple data units have been altered based on the first verification code and the second verification code may include: the second communication device concatenating the first verification code with the second verification code to obtain a bit stream B, and then dividing the bit stream B by the binary code elements of the CRC generator polynomial using modulo-2 division. If there is no remainder after the division operation, it indicates that no error occurred during the transmission process and the multiple data units have not been altered. Otherwise, it indicates that an error occurred during the transmission process and the multiple data units may have been altered.

[0261] When the second verification code is the exclusive OR of the verification codes corresponding to the multiple data units, or when the verification codes corresponding to the multiple data units are used as input parameters and the second verification code is obtained through the operation of the integrity protection algorithm, in the above-mentioned step S905, the second communication device determines whether the multiple data units are changed based on the first verification code and the second verification code, which may include: when the first verification code and the second verification code are the same, it indicates that the multiple data units have not been changed; when the first verification code and the second verification code are different, it indicates that the multiple data units have been changed.

[0262] In mode B, the second communication device determines a first input parameter and determines a second verification code based on the first input parameter. The first input parameter includes a first bit stream and at least one of the following: a key (or integrity protection key), a value corresponding to the first PDU, a transmission direction of the first PDU, or a HARQ identifier corresponding to the first PDU.

[0263] Exemplarily, taking the example that the second verification code is obtained based on the key, the value corresponding to the first PDU, the first bit stream and the transmission direction of the first PDU, the schematic diagram of the second communication device determining the second verification code can be shown in Figure 14.

[0264] The specific implementation of method B can refer to the description of method 2 above, which will not be repeated here. It can be understood that when the first communication device determines the first verification code through method 2 above, the second communication device determines the second verification code through method B.

[0265] As a possible implementation, when the header of the first PDU includes the second information, the second communication device can determine whether integrity protection is performed on the first PDU or all data units of the first PDU based on the second information.

[0266] As another possible implementation, when the scheduling information of the first TB includes the third information, the second communication device can determine whether the integrity protection is performed on the first PDU or all data units of the first PDU based on the third information.

[0267] As another possible implementation, when the header of the first PDU includes fourth information, the second communication device may determine the above-mentioned multiple data units based on the fourth information.

[0268] Exemplarily, when the second communication device determines the second verification code through method B, in the above step S905, the second communication device determines whether multiple data units are changed based on the first verification code and the second verification code, which may include: when the first verification code and the second verification code are the same, it indicates that the multiple data units have not been changed; when the first verification code and the second verification code are different, it indicates that the multiple data units have been changed.

[0269] The above scheme protects the integrity of the data unit of the first protocol layer. In addition, the present application also provides a data processing method for encrypting the data unit of the first protocol layer. As shown in Figure 15, the data processing method includes the following steps:

[0270] S1501. A first communication device determines a plurality of data units of a first protocol layer.

[0271] For the description of the first communication device and the first protocol layer, reference may be made to the related description of the first communication device and the first protocol layer in the above step S901, which will not be repeated here.

[0272] In one possible implementation, the multiple data units may be understood as data units that require encryption. For example, there may be multiple encryption algorithms for encrypting data, such as the Advanced Encryption Standard (AES) algorithm, the Data Encryption Standard (DES) algorithm, and the Triple DES (3DES) algorithm. The specific encryption algorithm used is not specifically limited in this embodiment of the present application.

[0273] As a possible implementation, when a data unit of the first protocol layer is a PDU of an upper protocol layer of the first protocol layer (called the second protocol layer), such as a MAC SDU, when an entity of the second protocol layer submits the data unit to an entity of the first protocol layer, it can send indication information to the entity of the first protocol layer to indicate that the data unit needs to be encrypted.

[0274] As another possible implementation, when a data unit of the first protocol layer is a data unit generated by an entity of the first protocol layer, such as a MAC CE, the first protocol layer may determine whether the data unit needs to be encrypted based on the implementation. For details on whether the data unit needs integrity protection in step S901 above, reference may be made to the description thereof, which will not be repeated here.

[0275] As another possible implementation, the protocol may predefine or the RAN node may preconfigure at least one LCID or at least one LCG identifier, and the data unit corresponding to the at least one LCID or LCG identifier is the data unit that needs to be encrypted. In this scenario, the first communication device can determine the above-mentioned multiple data units based on the at least one LCID or LCG identifier. Please refer to the description of whether the data unit needs integrity protection and the related implementation of LCID, LCG identifier, etc. in step S901 above, and will not be repeated here.

[0276] S1502. The first communication device determines a first ciphertext.

[0277] The first ciphertext is obtained by encrypting the above-mentioned multiple data units. The specific implementation will be described in detail in the subsequent embodiments and will not be described in detail here.

[0278] S1503: The first communication device outputs a first PDU. Correspondingly, the second communication device receives the first PDU, wherein the first PDU includes a first ciphertext.

[0279] Among them, the implementation of the second communication device, the first PDU, the relationship between the above-mentioned multiple data units and the first PDU, etc. can refer to the relevant description in the above-mentioned step S903, and will not be repeated here.

[0280] S1504: The second communication device decrypts the first ciphertext.

[0281] In a possible implementation, the second communication device successfully decrypts the first ciphertext to obtain plaintext, or in other words, obtains the plaintext of the multiple data units included in the first PDU.

[0282] In a possible implementation, the second communication device decrypts the first ciphertext using the parameters used by the first communication device to determine the first ciphertext, which will be described in detail in subsequent embodiments and will not be repeated here.

[0283] Based on the above scheme, the sending end can encrypt the data unit of the first protocol layer. Since the first protocol layer is usually located below the PDCP layer, or is usually a relatively low-level protocol layer, the scheme of the present application encrypts the data unit of the low-level protocol layer. Since the PDU of the high-level protocol layer is usually used as the data unit of the low-level protocol layer, it can be considered that the scheme of the present application encrypts the PDU of the high-level protocol layer (including the user plane PDU and the control plane PDU) at the first protocol layer, thereby preventing the leakage of information carried by the data unit and preventing illegal devices from changing the data unit, thereby improving the security performance of data transmission and user experience.

[0284] The above describes the overall process of the data processing method provided by this application. The following describes the specific implementation of the first communication device determining the first ciphertext in step 1502 and the second communication device decrypting the first ciphertext in step S1504. For example, the first communication device can determine the first ciphertext in the following two ways:

[0285] Method 1: The first communication device determines ciphertexts corresponding to the plurality of data units, and then determines a first ciphertext based on the ciphertexts corresponding to the plurality of data units.

[0286] As a possible implementation, taking multiple data units including a first data unit as an example, the ciphertext corresponding to the first data unit is obtained based on the first data unit and at least one of the following items, or in other words, the input parameters for encrypting the first data unit include the first data unit and at least one of the following items: a key (or encryption key), a numerical value corresponding to the first PDU, a transmission direction of the first PDU, a HARQ identifier corresponding to the first PDU, an LCID corresponding to the first data unit, a wireless bearer identifier corresponding to the first data unit, a type parameter of the first data unit, or a key stream length.

[0287] The key stream length refers to the length of the key stream used for encryption / decryption (such as the first key stream or the second key stream described below). The description of the remaining parameters can refer to the relevant description of the integrity protection scheme method 1 above, and will not be repeated here.

[0288] Exemplarily, encrypting the first data unit may include: determining a first key stream based on a third input parameter, performing an XOR operation on the first key stream and the first data unit to obtain a ciphertext corresponding to the first data unit. The third input parameter may include at least one of the following: a key (or encryption key), a value corresponding to the first PDU, a transmission direction of the first PDU, a HARQ identifier corresponding to the first PDU, an LCID corresponding to the first data unit, a radio bearer identifier corresponding to the first data unit, a type parameter of the first data unit, or a key stream length (such as the length of the first key stream).

[0289] For example, taking the third input parameter including the encryption key, the numerical value corresponding to the first PDU, the transmission direction of the first PDU, the LCID corresponding to the first data unit, and the key stream length as an example, the schematic diagram of the first communication device determining the ciphertext corresponding to the first data unit can be shown in Figure 16.

[0290] It can be understood that the first data unit is any one of the above-mentioned multiple data units. That is, the implementation of the ciphertext corresponding to each of the above-mentioned multiple data units can refer to the implementation of the ciphertext corresponding to the first data unit.

[0291] As a possible implementation, the first ciphertext is a collection of ciphertexts corresponding to multiple data units, that is, the first ciphertext includes ciphertexts corresponding to multiple data units.

[0292] Optionally, the ciphertext corresponding to the data unit may be located in a sub-PDU included in the first PDU, and in the sub-header of the sub-PDU, the first communication device may indicate whether the data unit corresponding to the sub-PDU is encrypted.

[0293] When the multiple data units include the first data unit, the first PDU may include a first sub-PDU, and the ciphertext corresponding to the first data unit may be located in the first sub-PDU. Furthermore, the subheader of the first sub-PDU may include first information, where the first information indicates that the first data unit has been encrypted. The specific implementation of the first information can be found in the description of the first information in Method 1 of the integrity protection scheme described above and is not further described here.

[0294] Method 2: The first communication device determines a second input parameter and determines the first ciphertext based on the second input parameter. The second input parameter includes the first bit stream and at least one of the following: a key (or encryption key), a value corresponding to the first PDU, a transmission direction of the first PDU, a HARQ identifier corresponding to the first PDU, or a key stream length.

[0295] As a possible implementation, the first bit stream is a collection of the above-mentioned multiple data units, or the first bit stream is a collection of sub-PDUs in which the above-mentioned multiple data units are located. Please refer to the relevant description in the second method of the above-mentioned integrity protection solution, which will not be repeated here.

[0296] As a possible implementation, determining the first ciphertext based on the second input parameter may include: determining a second key stream according to a fourth input parameter, and performing an XOR operation on the second key stream and the first bit stream to obtain the first ciphertext.

[0297] Exemplarily, the fourth input parameter includes the parameters in the second input parameter excluding the first bit stream. That is, the fourth input parameter may include at least one of the following: a key (or encryption key), a value corresponding to the first PDU, a transmission direction of the first PDU, a HARQ identifier corresponding to the first PDU, or a key stream length (such as the length of the second key stream).

[0298] In one possible embodiment, when the above-mentioned multiple data units are all data units of the first PDU, the header of the first PDU may include second information, which can be used to indicate that the first PDU (or all sub-PDUs of the first PDU) or all data units of the first PDU are encrypted.

[0299] In another possible embodiment, when the above-mentioned multiple data units are all data units of the first PDU, the first PDU is located in the first TB or the first PDU is the first TB, the first communication device further determines the scheduling information of the first TB, and the scheduling information may include third information, and the third information is used to indicate that the PDU included in the first TB or all data units in the PDU need to be encrypted. The first communication device can learn based on the third information that the first PDU (or all sub-PDUs of the first PDU) or all data units of the first PDU need to be encrypted. At the receiving end, the second communication device can also learn based on the third information that the first communication device has encrypted the first PDU or all data units of the first PDU.

[0300] In another possible implementation, when the multiple data units are part of the data units in the first PDU, the header of the first PDU may include fourth information, where the fourth information is used to indicate that the multiple data units or the sub-PDUs containing the multiple data units are encrypted.

[0301] Among them, the implementation of the second information, the third information, and the fourth information can refer to the relevant description in the second method of the above-mentioned integrity protection solution, and will not be repeated here.

[0302] Exemplarily, the second communication device can decrypt the first ciphertext in the following two ways:

[0303] Method A: When the first ciphertext is a collection of ciphertexts corresponding to a plurality of data units, the second communication device decrypts the ciphertexts corresponding to the plurality of data units.

[0304] As one possible implementation, the second communication device can determine the first key stream based on the third input parameter and perform XOR operation on the key stream and the ciphertext corresponding to the multiple data units to obtain the multiple data units. The third input parameter can be referred to the relevant description in the first embodiment above and will not be repeated here.

[0305] For example, taking the example where multiple data units include a first data unit, and the third input parameter includes an encryption key, a numerical value corresponding to the first PDU, a transmission direction of the first PDU, an LCID corresponding to the first data unit, and a key stream length, the schematic diagram of the second communication device decrypting the ciphertext corresponding to the first data unit can be shown in Figure 16.

[0306] As a possible implementation, when the first communication device indicates in the subheader of the sub-PDU whether the data units in the sub-PDU are encrypted, the second communication device can determine the multiple data units based on the indication. That is, the multiple data units are the encrypted data units in the first PDU.

[0307] As another possible implementation, the second communication device can determine at least one LCID or at least one LCG identifier, and the data unit corresponding to the at least one LCID or LCG identifier is the data unit that needs to be encrypted. In this scenario, the second communication device can determine the above-mentioned multiple data units based on the at least one LCID or LCG identifier. For example, if the LCID of a data unit belongs to the at least one LCID mentioned above, and / or the LCG identifier of the data unit belongs to the at least one LCG identifier mentioned above, it means that the data unit is an encrypted data unit.

[0308] The specific implementation of method A can refer to the description of method 1 above, which will not be repeated here. It can be understood that when the first communication device determines the first ciphertext through method 1 above, the second communication device decrypts the first ciphertext through method A.

[0309] In method B, the second communication device decrypts the first ciphertext using the second key stream. The second key stream is determined based on the fourth input parameter. The fourth input parameter can be referred to the relevant description in the above method 2 and will not be repeated here.

[0310] As a possible implementation, the second communication device determines a second key stream according to the fourth input parameter, performs an XOR operation on the second key stream and the first ciphertext to obtain a first bit stream, and further obtains the above-mentioned multiple data units.

[0311] As a possible implementation, when the header of the first PDU includes the second information, the second communication device can determine whether the first PDU or all data units of the first PDU are encrypted based on the second information.

[0312] As another possible implementation, when the scheduling information of the first TB includes the third information, the second communication device may determine, based on the third information, whether the first PDU or all data units of the first PDU are encrypted.

[0313] As another possible implementation, when the header of the first PDU includes fourth information, the second communication device may determine the above-mentioned multiple data units based on the fourth information.

[0314] It should be noted that the data processing methods for integrity protection / verification related to Figures 9-14 and the data processing methods for encryption / decryption related to Figures 15-16 can be executed independently of each other, or they can be combined with each other. For example, the sender can first encrypt the data using the methods related to Figures 15-16, and then use the methods related to Figures 9-14 to perform integrity protection on the encrypted data; or, it can encrypt the data using the methods related to Figures 15-16 and use the methods related to Figures 9-14 to perform integrity protection on the plaintext data; or, it can encrypt part of the data using the methods related to Figures 15-16 and use the methods related to Figures 9-14 to perform integrity protection on another part of the plaintext data. This application does not specifically limit the combination of the two.

[0315] In addition, when the data processing method for integrity protection / verification and the data processing method for encryption / decryption are executed in combination, the sending end may carry indication information in the sub-header of the sub-PDU or the header of the PDU to indicate the encrypted data unit and / or the integrity-protected data unit. Please refer to the relevant implementation of the first to fourth information mentioned above and will not be repeated here.

[0316] It should be noted that, in this application, "sending information to... (communication device)" can be understood as the destination end of the information being the communication device. It can include sending information to the communication device directly or indirectly. "Receiving information from... (communication device)" can be understood as the source end of the information being the communication device, which can include receiving information from the communication device directly or indirectly. The information may be processed as necessary between the source end and the destination end of the information transmission, such as format changes, etc., but the destination end can understand the valid information from the source end. Similar expressions in this application can be understood similarly and will not be repeated here.

[0317] It is understood that in each of the above embodiments, the methods and / or steps implemented by the first communication device may also be implemented by components applicable to the first communication device (e.g., a processor, chip, chip system, circuit, logic module, or software); and the methods and / or steps implemented by the second communication device may also be implemented by components applicable to the second communication device (e.g., a processor, chip, chip system, circuit, logic module, or software). The chip system may be composed of a chip, or may include a chip and other discrete components.

[0318] Exemplarily, when the methods and / or steps implemented by the first communication device / second communication device are implemented by components that can be used for the first communication device / second communication device, the above-mentioned sending action / function can be understood as output information, and the above-mentioned receiving action / function can be understood as input information.

[0319] It is understandable that, in order to realize the above functions, the communication device includes hardware structures and / or software modules corresponding to the execution of each function. It should be easily appreciated by those skilled in the art that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0320] The embodiment of the present application can divide the functional modules of the communication device according to the above method embodiment. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. In actual implementation, there may be other division methods.

[0321] Communication Device Figure 17 shows a schematic structural diagram of a communication device 170. The communication device 170 includes a processing module 1701 and a transceiver module 1702. The communication device 170 can be used to implement the functions of the first communication device or the second communication device described above.

[0322] In some embodiments, the communication device 170 may further include a storage module (not shown in FIG. 17 ) for storing program instructions and data.

[0323] In some embodiments, the transceiver module 1702, which may also be referred to as a transceiver unit, is configured to implement a transmitting and / or receiving function. The transceiver module 1702 may be composed of a transceiver circuit, a transceiver, a transceiver, or a communication interface.

[0324] In some embodiments, the transceiver module 1702 may include a receiving module and a sending module, which are respectively used to execute the receiving and sending steps performed by the first communication device or the second communication device in the above method embodiments, and / or used to support other processes of the technology described herein; the processing module 1701 may be used to execute the processing steps (such as determination, etc.) performed by the first communication device or the second communication device in the above method embodiments, and / or used to support other processes of the technology described herein.

[0325] When the communication device 170 is used to implement the function of the first communication device, in a possible implementation manner:

[0326] The processing module 1701 is used to determine multiple data units of the first protocol layer, where the first protocol layer is a lower protocol layer of the Packet Data Convergence Protocol (PDCP) layer; the processing module 1701 is also used to determine a first verification code for verifying the integrity of the multiple data units; the transceiver module 1702 is used to output a first protocol data unit (PDU) including the multiple data units and the first verification code.

[0327] Optionally, the processing module 1701 is used to determine the first verification code, including: the processing module 1701 is used to determine the verification codes corresponding to the multiple data units respectively; the processing module 1701 is further used to determine the first verification code according to the verification codes corresponding to the multiple data units respectively.

[0328] Optionally, the processing module 1701 is used to determine multiple data units of the first protocol layer, including: the processing module 1701 is used to determine multiple data units based on at least one logical channel identifier LCID or at least one logical channel group LCG identifier, and the data unit corresponding to the at least one LCID or LCG identifier is a data unit that needs to be integrity protected. The at least one LCID includes the LCID of each data unit in the above-mentioned multiple data units, or the at least one LCG identifier includes the LCG identifier of each data unit in the above-mentioned multiple data units.

[0329] Optionally, the first PDU is located in a first transport block (TB); the multiple data units are all data units in the first PDU. Processing module 1701 is further configured to determine scheduling information for the first TB, the scheduling information including third information, the third information being configured to indicate that integrity protection is required for the PDU or all data units in the PDU included in the first TB.

[0330] When the communication device 170 is used to implement the function of the first communication device, in another possible implementation:

[0331] The processing module 1701 is used to determine multiple data units of the first protocol layer, where the first protocol layer is a lower protocol layer of the Packet Data Convergence Protocol (PDCP) layer; the processing module 1701 is also used to determine a first ciphertext, which is obtained by encrypting multiple data units; the transceiver module 1702 is used to output a first protocol data unit (PDU) including the first ciphertext.

[0332] Optionally, the processing module 1701 is used to determine the first ciphertext, including: the processing module 1701 is used to determine the ciphertexts corresponding to the multiple data units; the processing module 1701 is also used to determine the first verification code according to the ciphertexts corresponding to the multiple data units.

[0333] Optionally, processing module 1701 is configured to determine multiple data units of the first protocol layer, including: processing module 1701 is configured to determine multiple data units based on at least one logical channel identifier LCID or at least one logical channel group LCG identifier, where the data unit corresponding to the at least one LCID or LCG identifier is a data unit that needs to be encrypted. The at least one LCID includes the LCID of each data unit in the multiple data units, or the at least one LCG identifier includes the LCG identifier of each data unit in the multiple data units.

[0334] Optionally, the first PDU is located in the first transmission block TB; the multiple data units are all data units in the first PDU, and the processing module 1701 is also used to determine the scheduling information of the first TB, and the scheduling information includes third information, and the third information is used to indicate that the PDU included in the first TB or all data units in the PDU need to be encrypted.

[0335] When the communication device 170 is used to implement the function of the second communication device, in a possible implementation:

[0336] The transceiver module 1702 is used to receive a first protocol data unit PDU, where the first PDU includes multiple data units and a first verification code of a first protocol layer, where the first protocol layer is a lower protocol layer of the packet data convergence protocol PDCP layer, and the first verification code is used to verify the integrity of the multiple data units; the processing module 1701 is used to determine a second verification code, where the second verification code is used to verify the integrity of the multiple data units; the processing module 1701 is also used to determine whether the multiple data units have been changed based on the first verification code and the second verification code.

[0337] Optionally, the processing module 1701 is used to determine the second verification code, including: the processing module 1701 is used to determine the verification codes corresponding to the multiple data units respectively; the processing module 1701 is further used to determine the second verification code according to the verification codes corresponding to the multiple data units respectively.

[0338] Optionally, processing module 1701 is further configured to determine at least one logical channel identifier (LCID) or at least one logical channel group (LCG) identifier, where the data unit corresponding to the at least one LCID or LCG identifier is a data unit requiring integrity protection. The at least one LCID includes the LCID of each data unit in the plurality of data units, or the at least one LCG identifier includes the LCG identifier of each data unit in the plurality of data units.

[0339] Optionally, the first PDU is located in a first transport block (TB); the multiple data units are all data units in the first PDU. Processing module 1701 is further configured to determine scheduling information for the first TB, the scheduling information including third information, the third information being configured to indicate that integrity protection is required for the PDU or all data units in the PDU included in the first TB.

[0340] When the communication device 170 is used to implement the function of the second communication device, in another possible implementation:

[0341] The transceiver module 1702 is used to receive a first protocol data unit PDU, which includes a first ciphertext. The first ciphertext is obtained by encrypting multiple data units of the first protocol layer, and the first protocol layer is a lower protocol layer of the packet data convergence protocol PDCP layer; the processing module 1701 is used to decrypt the first ciphertext.

[0342] Optionally, the multiple data units include a first data unit, and the first ciphertext includes a ciphertext corresponding to the first data unit. Processing module 1701, used to decrypt the first ciphertext, includes: processing module 1701, used to determine a first key stream based on a third input parameter; processing module 1701, further used to XOR the first key stream and the ciphertext corresponding to the first data unit to obtain the first data unit. The third input parameter includes at least one of the following: a key, a numerical value corresponding to the first PDU, a transmission direction of the first PDU, a hybrid automatic repeat request HARQ identifier corresponding to the first PDU, an LCID corresponding to the first data unit, a radio bearer identifier corresponding to the first data unit, a type parameter of the first data unit, or a key stream length. The numerical value corresponding to the first PDU is used to identify the first PDU, or to indicate the time domain and / or frequency domain position of the first PDU.

[0343] Optionally, processing module 1701 is configured to determine at least one logical channel identifier (LCID) or at least one logical channel group (LCG) identifier, where the data unit corresponding to the at least one LCID or LCG identifier is a data unit that needs to be encrypted. The at least one LCID includes the LCID of each data unit in the plurality of data units, or the at least one LCG identifier includes the LCG identifier of each data unit in the plurality of data units.

[0344] Optionally, the processing module 1701 is used to decrypt the first ciphertext, including: the processing module 1701 is used to determine the second key stream based on the fourth input parameter; the processing module 1701 is also used to XOR the second key stream and the first ciphertext to obtain a first bit stream. The fourth input parameter includes at least one of the following: a key, a numerical value corresponding to the first PDU, a transmission direction of the first PDU, a HARQ identifier corresponding to the first PDU, or a key stream length, and the numerical value corresponding to the first PDU is used to identify the first PDU or to indicate the time domain and / or frequency domain position of the first PDU. The first bit stream is a collection of multiple data units, or the first bit stream is a collection of sub-PDUs where multiple data units are located.

[0345] Optionally, the first PDU is located in the first transmission block TB; the multiple data units are all data units in the first PDU; the processing module 1701 is also used to determine the scheduling information of the first TB, the scheduling information includes third information, and the third information is used to indicate that the PDU included in the first TB or all data units in the PDU need to be encrypted.

[0346] Among them, all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module, that is, all features involved in the above method embodiment are applicable to the above communication device and will not be repeated here.

[0347] In the present application, the communication device 170 may be presented in the form of various functional modules divided in an integrated manner. The "module" here may refer to a specific application-specific integrated circuit (ASIC), a circuit, a processor and memory that executes one or more software or firmware programs, an integrated logic circuit, and / or other devices that can provide the above functions.

[0348] In some embodiments, when the communication device 170 in Figure 17 is a chip or a chip system, the function / implementation process of the transceiver module 1702 can be implemented through the input and output interface (or communication interface) of the chip or chip system, and the function / implementation process of the processing module 1701 can be implemented through the processor (or processing circuit) of the chip or chip system.

[0349] Since the communication device 170 provided in this embodiment can execute the above method, the technical effects that can be obtained can refer to the above method embodiments and will not be repeated here.

[0350] As a possible product form, the first communication device or the second communication device described in the embodiments of the present application can also be implemented using the following: one or more field programmable gate arrays (FPGAs), programmable logic devices (PLDs), controllers, state machines, gate logic, discrete hardware components, any other suitable circuits, or any combination of circuits that can perform the various functions described throughout this application.

[0351] As another possible product form, the first communication device or the second communication device described in the embodiment of the present application can be implemented by a general bus architecture. For ease of explanation, refer to Figure 18, which is a structural diagram of a communication device 1800 provided in an embodiment of the present application, and the communication device 1800 includes a processor 1801 and a transceiver 1802. The communication device 1800 can be a first communication device, or a chip or chip system therein; or, the communication device 1800 can be a second communication device, or a chip or module therein. Figure 18 only shows the main components of the communication device 1800. In addition to the processor 1801 and the transceiver 1802, the communication device may further include a memory 1803, and an input and output device (not shown in the figure).

[0352] Optionally, the processor 1801 is mainly used to process the communication protocol and communication data, as well as to control the entire communication device, execute the software program, and process the data of the software program, thereby implementing the method provided in the above method embodiment. The memory 1803 is mainly used to store software programs and data. The transceiver 1802 may include a radio frequency circuit and an antenna. The radio frequency circuit is mainly used to convert baseband signals into radio frequency signals and process radio frequency signals. The antenna is mainly used to transmit and receive radio frequency signals in the form of electromagnetic waves. Input and output devices, such as a touch screen, display screen, keyboard, etc., are mainly used to receive data input by the user and output data to the user.

[0353] Optionally, the processor 1801 , the transceiver 1802 , and the memory 1803 may be connected via a communication bus.

[0354] When the communication device is powered on, the processor 1801 can read the software program in the memory 1803, interpret and execute the instructions of the software program, and process the data of the software program. When data needs to be sent wirelessly, the processor 1801 performs baseband processing on the data to be transmitted and outputs the baseband signal to the radio frequency circuit. The radio frequency circuit performs radio frequency processing on the baseband signal and then transmits the radio frequency signal to the outside in the form of electromagnetic waves via the antenna. When data is sent to the communication device, the radio frequency circuit receives the radio frequency signal via the antenna, converts the radio frequency signal into a baseband signal, and outputs the baseband signal to the processor 1801. The processor 1801 converts the baseband signal into data and processes the data.

[0355] In another implementation, the RF circuit and antenna may be provided independently of the processor performing baseband processing. For example, in a distributed scenario, the RF circuit and antenna may be remotely arranged independent of the communication device.

[0356] In some embodiments, in terms of hardware implementation, those skilled in the art may conceive that the above-mentioned communication device 170 may take the form of a communication device 1800 shown in FIG. 18 .

[0357] As an example, the functions / implementation process of the processing module 1701 in FIG17 can be implemented by the processor 1801 in the communication device 1800 shown in FIG18 calling the computer-executable instructions stored in the memory 1803. The functions / implementation process of the transceiver module 1702 in FIG17 can be implemented by the transceiver 1802 in the communication device 1800 shown in FIG18.

[0358] As another possible product form, the first communication device or the second communication device in this application may adopt the structure shown in Figure 19, or include the components shown in Figure 19. Figure 19 is a schematic diagram of the structure of a communication device 1900 provided in this application. The communication device 1900 may be a first communication device or a chip or system-on-chip in the first communication device; or, it may be a second communication device or a module, chip, or system-on-chip in the second communication device.

[0359] As shown in FIG19 , the communication device 1900 includes at least one processor 1901 and at least one communication interface ( FIG19 is merely an example of one communication interface 1904 and one processor 1901). Optionally, the communication device 1900 may further include a communication bus 1902 and a memory 1903.

[0360] Processor 1901 can be a general-purpose central processing unit (CPU), a general-purpose processor, a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller, a programmable logic device (PLD), or any combination thereof. Processor 1901 can also be other devices with processing capabilities, such as circuits, devices, or software modules, without limitation.

[0361] Communication bus 1902 is used to connect the various components in communication device 1900, enabling communication between them. Communication bus 1902 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, for example. This bus can be categorized as an address bus, a data bus, a control bus, and so on. For ease of illustration, FIG19 shows a single bold line, but this does not imply that there is only one bus or type of bus.

[0362] Communication interface 1904 is used to communicate with other devices or communication networks. Exemplarily, communication interface 1904 can be a module, circuit, transceiver, or any other device capable of communication. Optionally, communication interface 1904 can also be an input / output interface within processor 1901, used to implement signal input and output to the processor.

[0363] The memory 1903 may be a device with a storage function, used to store instructions and / or data, wherein the instructions may be computer programs.

[0364] Exemplarily, the memory 1903 may be a read-only memory (ROM) or other types of static storage devices that can store static information and / or instructions, or a random access memory (RAM) or other types of dynamic storage devices that can store information and / or instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, etc., without limitation.

[0365] It should be noted that the memory 1903 can exist independently of the processor 1901 or can be integrated with the processor 1901. The memory 1903 can be located within the communication device 1900 or outside the communication device 1900, without limitation. The processor 1901 can be used to execute instructions stored in the memory 1903 to implement the methods provided in the following embodiments of the present application.

[0366] As an optional implementation, the communication device 1900 may further include an output device 1905 and an input device 1906. The output device 1905 communicates with the processor 1901 and can display information in a variety of ways. For example, the output device 1905 can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device 1906 communicates with the processor 1901 and can receive user input in a variety of ways. For example, the input device 1906 can be a mouse, a keyboard, a touch screen device, or a sensor device.

[0367] In some embodiments, in terms of hardware implementation, those skilled in the art may conceive that the communication device 170 shown in FIG. 17 may take the form of the communication device 1900 shown in FIG. 19 .

[0368] As an example, the functions / implementation process of the processing module 1701 in FIG17 can be implemented by the processor 1901 in the communication device 1900 shown in FIG19 calling the computer-executable instructions stored in the memory 1903. The functions / implementation process of the transceiver module 1702 in FIG17 can be implemented by the communication interface 1904 in the communication device 1900 shown in FIG19.

[0369] It should be noted that the structure shown in FIG19 does not constitute a specific limitation on the first communication device or the second communication device. For example, in other embodiments of the present application, the first communication device or the second communication device may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.

[0370] In some embodiments, an embodiment of the present application further provides a communication device, which includes a processor for implementing the method in any of the above method embodiments.

[0371] As a possible implementation, the communication device further includes a memory. The memory is used to store necessary computer programs and data. The computer program may include instructions, and the processor may invoke the instructions in the computer program stored in the memory to instruct the communication device to execute any of the above-described method embodiments. Of course, the memory may not be located in the communication device.

[0372] As another possible implementation, the communication device also includes an interface circuit, which is a code / data read / write interface circuit, and the interface circuit is used to receive computer execution instructions (computer execution instructions are stored in a memory, may be read directly from the memory, or may pass through other devices) and transmit them to the processor.

[0373] As another possible implementation, the communication device further includes a communication interface, where the communication interface is used to communicate with a module outside the communication device.

[0374] It can be understood that the communication device can be a chip or a chip system. When the communication device is a chip system, it can be composed of chips or include chips and other discrete devices. The embodiments of the present application do not specifically limit this.

[0375] The present application also provides a computer-readable storage medium having a computer program or instruction stored thereon, which implements the functions of any of the above method embodiments when executed by a computer.

[0376] The present application also provides a computer program product, which implements the functions of any of the above method embodiments when executed by a computer.

[0377] Those skilled in the art will appreciate that, for the sake of convenience and brevity of description, the specific working processes of the above-described systems, devices, and units may refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0378] It is understood that the systems, devices, and methods described in this application may also be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection shown or discussed may be through some interface, indirect coupling or communication connection of devices or units, and may be electrical, mechanical, or other forms.

[0379] The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Components shown as units may or may not be physical units. Some or all of these units may be selected to achieve the objectives of this embodiment as needed.

[0380] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0381] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented using a software program, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium (eg, a solid state drive (SSD)). In the embodiment of the present application, the computer may include the aforementioned device.

[0382] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art can understand and implement other changes to the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple situations. A single processor or other unit can implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0383] Although the present application has been described with reference to specific features and embodiments thereof, it is apparent that various modifications and combinations may be made thereto without departing from the scope of the present application. Accordingly, this specification and the drawings are merely illustrative of the present application as defined by the appended claims and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art may make various modifications and variations to the present application without departing from the scope of the present application. Thus, the present application is intended to include such modifications and variations as fall within the scope of the claims of the present application and their equivalents.

Claims

1. A data processing method, characterized in that, The method includes: Determining a plurality of data units of a first protocol layer, where the first protocol layer is a lower protocol layer of the Packet Data Convergence Protocol (PDCP) layer; Determining a first verification code, where the first verification code is used to verify the integrity of the plurality of data units; Outputting a first Protocol Data Unit (PDU), where the first PDU includes the plurality of data units and the first verification code.

2. The method according to claim 1, characterized in that, The determining of the first verification code includes: Determining verification codes respectively corresponding to the plurality of data units; Determining the first verification code according to the verification codes respectively corresponding to the plurality of data units.

3. The method according to claim 2, characterized in that, The first verification code is the exclusive OR of the verification codes respectively corresponding to the plurality of data units; or The first verification code is a verification code obtained by performing integrity protection on the verification codes respectively corresponding to the plurality of data units.

4. The method according to claim 2 or 3, characterized in that, The plurality of data units includes a first data unit, and the verification code corresponding to the first data unit is obtained based on the first data unit and at least one of the following: a key, a value corresponding to the first PDU, a transmission direction of the first PDU, a Hybrid Automatic Repeat reQuest (HARQ) identifier corresponding to the first PDU, a Logical Channel IDentifier (LCID) corresponding to the first data unit, a Radio Bearer identifier corresponding to the first data unit, or a type parameter of the first data unit, where the value corresponding to the first PDU is used to identify the first PDU or to indicate a time domain and / or frequency domain position where the first PDU is located.

5. The method according to any one of claims 2-4, characterized in that, The plurality of data units includes a first data unit, the first PDU includes a first sub-PDU, and the first data unit is located in the first sub-PDU; a first piece of information is included in a sub-header of the first sub-PDU, and the first piece of information is used to indicate that integrity protection has been performed on the first data unit.

6. The method according to any one of claims 2-4, characterized in that, The determining of the plurality of data units of the first protocol layer includes: Determining the plurality of data units of the first protocol layer according to at least one Logical Channel IDentifier (LCID) or at least one Logical Channel Group (LCG) identifier, where data units corresponding to the at least one LCID or LCG identifier are data units that need to perform integrity protection; The at least one LCID includes the LCID of each data unit in the plurality of data units, or the at least one LCG identifier includes the LCG identifier of each data unit in the plurality of data units.

7. The method according to claim 1, wherein The determining of the first verification code includes: Determining a first input parameter, where the first input parameter includes a first bit stream and at least one of the following: a key, a value corresponding to the first PDU, a transmission direction of the first PDU, or a Hybrid Automatic Repeat reQuest (HARQ) identifier corresponding to the first PDU; Determining the first verification code based on the first input parameter; where the first bit stream is a set of the plurality of data units, or the first bit stream is a set of sub-PDUs where the plurality of data units are located; the value corresponding to the first PDU is used to identify the first PDU or to indicate a time domain and / or frequency domain position where the first PDU is located.

8. The method according to claim 7, wherein The multiple data units are all the data units in the first PDU, and the header of the first PDU includes second information, where the second information is used to indicate that integrity protection has been performed on the first PDU or all the data units of the first PDU.

9. The method according to claim 7, wherein The first PDU is located in the first transport block TB; The multiple data units are all the data units in the first PDU; The method further includes: Determine the scheduling information of the first TB, where the scheduling information includes third information, and the third information is used to indicate that integrity protection is required for the PDU included in the first TB or all the data units in the PDU.

10. The method according to claim 7, wherein The multiple data units are partial data units in the first PDU, and the header of the first PDU includes fourth information, where the fourth information is used to indicate that integrity protection has been performed on the multiple data units or the sub-PDU where the multiple data units are located.

11. The method according to any one of claims 4 or 7 - 10, characterized in that When the value corresponding to the first PDU is used to identify the first PDU, the value corresponding to the first PDU is a sequence number SN or a count value COUNT; When the value corresponding to the first PDU is used to indicate the time domain and / or frequency domain position where the first PDU is located, the value corresponding to the first PDU is any one of the following: the system frame number SFN where the first PDU is located, a value obtained based on the SFN and the hyper-system frame number H-SFN where the first PDU is located, the index of the time domain resource where the first PDU is located, or the value of the time-frequency resource indication field; The value of the time-frequency resource indication field indicates the time-frequency resource used to carry the first PDU.

12. The method according to any one of claims 1-11, characterized in that, The first protocol layer is the media access control MAC layer, and the data unit includes a MAC service data unit SDU or a MAC control element CE.

13. A data processing method, characterized in that, The method includes: Receive a first protocol data unit PDU, where the first PDU includes multiple data units of a first protocol layer and a first verification code, the first protocol layer is the lower protocol layer of the packet data convergence protocol PDCP layer, and the first verification code is used to verify the integrity of the multiple data units; Determine a second verification code, where the second verification code is used to verify the integrity of the multiple data units; Determine whether the multiple data units have been changed according to the first verification code and the second verification code.

14. The method according to claim 13, wherein The determining the second verification code includes: Determine the verification codes respectively corresponding to the multiple data units; Determine the second verification code according to the verification codes respectively corresponding to the multiple data units.

15. The method according to claim 14, wherein The second verification code is the exclusive OR of the verification codes respectively corresponding to the multiple data units; or, The second verification code is the verification code obtained after performing integrity protection on the verification codes respectively corresponding to the multiple data units.

16. The method according to claim 14 or 15, characterized in that The multiple data units include a first data unit, and the verification code corresponding to the first data unit is obtained based on the first data unit and at least one of the following: a key, a value corresponding to the first PDU, a transmission direction of the first PDU, a hybrid automatic repeat request (HARQ) identifier corresponding to the first PDU, a logical channel identifier (LCID) corresponding to the first data unit, a radio bearer identifier corresponding to the first data unit, or a type parameter of the first data unit. The value corresponding to the first PDU is used to identify the first PDU or to indicate a time domain and / or frequency domain position where the first PDU is located.

17. The method according to any one of claims 14 to 16, characterized in that The multiple data units include a first data unit, the first PDU includes a first sub-PDU, and the first data unit is located in the first sub-PDU; a first piece of information is included in a sub-header of the first sub-PDU, and the first piece of information is used to indicate that integrity protection has been performed on the first data unit.

18. The method according to any one of claims 14-16, characterized in that, The method further includes: determining at least one logical channel identifier (LCID) or at least one logical channel group (LCG) identifier, where data units corresponding to the at least one LCID or LCG identifier are data units that need to be integrity protected; The at least one LCID includes LCIDs of each data unit in the multiple data units, or the at least one LCG identifier includes LCG identifiers of each data unit in the multiple data units.

19. The method according to claim 13, wherein The determining the second verification code includes: determining a first input parameter, where the first input parameter includes a first bit stream and at least one of the following: a key, a value corresponding to the first PDU, a transmission direction of the first PDU, or a hybrid automatic repeat request (HARQ) identifier corresponding to the first PDU; determining the second verification code based on the first input parameter; where the first bit stream is a set of the multiple data units, or the first bit stream is a set of sub-PDUs where the multiple data units are located; the value corresponding to the first PDU is used to identify the first PDU or to indicate a time domain and / or frequency domain position where the first PDU is located.

20. The method according to claim 19, wherein The multiple data units are all data units in the first PDU, and a second piece of information is included in a header of the first PDU, and the second piece of information is used to indicate that integrity protection has been performed on the first PDU or all data units of the first PDU.

21. The method according to claim 19, wherein The first PDU is located in a first transport block (TB); The multiple data units are all data units in the first PDU; the method further includes: determining scheduling information of the first TB, where the scheduling information includes a third piece of information, and the third piece of information is used to indicate that PDUs included in the first TB or all data units in the PDUs need to be integrity protected.

22. The method according to claim 19, wherein The multiple data units are partial data units in the first PDU, and a fourth piece of information is included in a header of the first PDU, and the fourth piece of information is used to indicate that integrity protection has been performed on the multiple data units or the sub-PDU where the multiple data units are located.

23. The method according to any one of claims 16 or 19 - 22, characterized in that, When the value corresponding to the first PDU is used to identify the first PDU, the value corresponding to the first PDU is a sequence number SN or a count value COUNT; When the value corresponding to the first PDU is used to indicate the time domain and / or frequency domain position where the first PDU is located, the value corresponding to the first PDU is any one of the following: the system frame number SFN where the first PDU is located, a value obtained based on the SFN and the hyper system frame number H-SFN where the first PDU is located, the index of the time domain resource where the first PDU is located, or the value of the time-frequency resource indication field; the value of the time-frequency resource indication field indicates the time-frequency resource used to carry the first PDU.

24. The method according to any one of claims 13-23, characterized in that, The first protocol layer is the media access control MAC layer, and the data unit includes a MAC service data unit SDU or a MAC control element CE.

25. A communication method, characterized in that, The method includes: A first communication device determines a plurality of data units and a first verification code of a first protocol layer, where the first protocol layer is a lower protocol layer of the packet data convergence protocol PDCP layer, and the first verification code is used to verify the integrity of the plurality of data units; The first communication device outputs a first protocol data unit PDU, and a second communication device receives the first PDU, where the first PDU includes the plurality of data units and the first verification code; The second communication device determines a second verification code, where the second verification code is used to verify the integrity of the plurality of data units; The second communication device determines whether the plurality of data units have been changed according to the first verification code and the second verification code.

26. A communication device, characterized in that, The communication device includes a module for executing the method according to any one of claims 1-12, or includes a module for executing the method according to any one of claims 13-24.

27. A communication device, characterized in that, The communication device includes a processor; the processor is configured to run a computer program or instruction to cause the communication device to execute the method according to any one of claims 1-12, or to cause the communication device to execute the method according to any one of claims 13-24.

28. A communication system, characterized in that, The communication system includes a first communication device and a second communication device; The first communication device is configured to execute the method according to any one of claims 1-12, and the second communication device is configured to execute the method according to any one of claims 13-24.

29. A chip or chip system, characterized in that, The chip or chip system includes a processor, the processor is coupled to a memory, and the memory is used to store a program or instruction. When the program or instruction is executed by the processor, the method according to any one of claims 1-12 is executed, or the method according to any one of claims 13-24 is executed.

30. A computer-readable storage medium, characterized in that, A computer-readable storage medium stores computer instructions or programs. When the computer instructions or programs are run on a computer, the method according to any one of claims 1-12 is executed, or the method according to any one of claims 13-24 is executed.

31. A computer program product, characterized in that, The computer program product includes computer instructions; when part or all of the computer instructions are run on a computer, the method according to any one of claims 1-12 is caused to be executed, or the method according to any one of claims 13-24 is caused to be executed.

Citation Information

Patent Citations

  • Data processing method and device

    CN120238868A

  • Method and apparatus for transmitting data unit based on selective application of integrity protection in wireless communication system

    CN115336305A

  • Communication method and device

    CN115696319A

  • Communication method and device

    CN116801253A

  • Method and apparatus for performing integrity verification in wireless communication system

    US20190297502A1